CVE-2013-0292

Freedesktop Dbus-glib < 0.100 - Improper Input Validation

Title source: rule

Description

The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.

Exploits (2)

github WORKING POC
by gitcollect · cpoc
https://github.com/gitcollect/CVE_Exploits/tree/master/cve-2013-0292
exploitdb WORKING POC
by Sebastian Krahmer · clocallinux
https://www.exploit-db.com/exploits/33614

Scores

EPSS 0.0022
EPSS Percentile 44.6%

Classification

CWE
CWE-20
Status draft

Affected Products (16)

freedesktop/dbus-glib < 0.100
freedesktop/dbus-glib
freedesktop/dbus-glib
freedesktop/dbus-glib
freedesktop/dbus-glib
freedesktop/dbus-glib
freedesktop/dbus-glib
freedesktop/dbus-glib
freedesktop/dbus-glib
freedesktop/dbus-glib
freedesktop/dbus-glib
freedesktop/dbus-glib
freedesktop/dbus-glib
freedesktop/dbus-glib
freedesktop/dbus-glib
... and 1 more

Timeline

Published Mar 05, 2013
Tracked Since Feb 18, 2026