Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An attacker could send crafted input to NetworkManager and ModemManager
and cause them to crash.
Software Description:
- modemmanager: Modem connection manager
- network-manager: Network connection manager
Details:
USN-1138-1 fixed a vulnerability in DBus-GLib. NetworkManager and
ModemManager required rebuilding against the updated DBus-GLib to
incorporate the changes.
Original advisory details:
It was discovered that DBus-GLib did not properly verify the access flag of
exported GObject properties under certain circumstances. A local attacker
could exploit this to bypass intended access restrictions or possibly
cause a denial of service.
The problem can be corrected by updating your system to the following package versions: Ubuntu 10.04 LTS: libnm-glib2 0.8-0ubuntu3.2 modemmanager 0.3-0ubuntu2.2 Ubuntu 8.04 LTS: libnm-glib0 0.6.6-0ubuntu5.8.04.3 After a standard system update you need to reboot your computer to make all the necessary changes.
https://bugs.launchpad.net/ubuntu/+source/dbus-glib/+bug/616517
Get the latest Linux and open source security news straight to your inbox.