Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libdbus 权限许可和访问控制问题漏洞
Vulnerability Description
libdbus是Freedesktop的一个低级库,旨在成为语言绑定的后端,并且需要额外的复杂性来实现 dbus-daemon。 libdbus 存在权限许可和访问控制问题漏洞。本地攻击者可利用该漏洞通过DBUS_SYSTEM_BUS_ADDRESS环境变量获取特权并执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A