D-BUS (dbus) before 0.22 does not properly restrict...
Low severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Jun 29, 2005
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Jan 30, 2023
D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.
References