D-BUS (dbus) before 0.22 does not properly restrict...
Low severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Apr 3, 2025
Description
Published by the National Vulnerability Database
Jun 29, 2005
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Apr 3, 2025
D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.
References