Improper Authentication in D-Bus - CVE-2019-12749

 

Improper Authentication in D-Bus - CVE-2019-12749

Published: July 21, 2019


Vulnerability identifier: #VU19274
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12749
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a an attacker to bypass authentication process.

The vulnerability exists due to an error when handling symlinks within the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. A malicious client with access to to its own home directory can manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write into unintended locations.

Successful exploitation of the vulnerability may allow an attacker to bypass DBUS_COOKIE_SHA1 authentication mechanis.


Affected software

D-Bus
Gentoo Linux
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
Ansible Automation Platform
dbus (Debian package)
dbus (Alpine package)
dbus (Red Hat package)
dbus
Red Hat OpenShift Container Platform
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell PowerProtect Cyber Recovery

How to mitigate CVE-2019-12749

Install updates from vendor's website.

D-Bus - addressed in versions 1.10.28, 1.12.6, 1.13.12
Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
dbus (Debian package) - update to 1.10.28-0+deb9u1
dbus (Alpine package) - addressed in versions 1.10.28-r0, 1.12.16-r0
dbus (Red Hat package) - update to 1.10.24-15.el7
dbus - update to 1.12.16-1.fc30
Red Hat OpenShift Container Platform - update to 4.3.40
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8

External References

Related Security Bulletins