Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2009-1189
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2009-1189

Description:
The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/50385

UBUNTU
  http://www.ubuntulinux.org/support/documentation/usn/usn-799-1

SAID
  Secunia Advisory: SA32127
  Secunia Advisory: SA35810

MLIST
  http://www.openwall.com/lists/oss-security/2009/04/16/13

CONFIRM
  http://www.freedesktop.org/wiki/Software/dbus#head-dad0dab297a44f1d7a3b1259cfc06b583fd6a88a
  http://bugs.freedesktop.org/show_bug.cgi?id=17803

BID
  31602


Return to the previous page.