Vulnerability CVE-2019-12749: Information

Description

dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing authentication bypass.

Severity: HIGH (7.1) Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Published: June 11, 2019
Modified: Nov. 7, 2023
Error type identifier: CWE-59

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
dbussisyphus1.12.16-alt11.14.10-alt1ALT-PU-2019-3092-1240314Fixed
dbusp101.12.16-alt11.14.10-alt1ALT-PU-2019-3092-1240314Fixed
dbusp91.12.16-alt21.12.16-alt2ALT-PU-2019-3127-1240607Fixed
dbusc10f11.12.16-alt11.14.8-alt1ALT-PU-2019-3092-1240314Fixed
dbusc9f21.12.16-alt21.12.16-alt2.c9f2.1ALT-PU-2019-3127-1240607Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:*
      Start including
      1.13.0
      End excliding
      1.13.12

      cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:*
      Start including
      1.12.0
      End excliding
      1.12.16

      cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:*
      End excliding
      1.10.28

      Configuration 2

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*