Oval Definition:oval:com.ubuntu.precise:def:20123524000
Revision Date:2012-09-18Version:1
Title:CVE-2012-3524 on Ubuntu 12.04 LTS (precise) - medium.
Description:libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."
Family:unixClass:vulnerability
Status:Reference(s):CVE-2012-3524
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The 'dbus' package in precise was vulnerable but has been fixed (note: '1.4.18-1ubuntu1.1').
  • BACK