Security controls bypass or absence In xdg-dbus-proxy
Description
xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Clients can intercept D-Bus messages they should not have access to. This vulnerability is fixed in 0.1.7.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 0.1.2-2+deb11u1 | ||
rpm rhel10 | - | - | |
debian 14 | 0.1.7-1 | ||
debian 12 | 0.1.4-3+deb12u1 | ||
debian 13 | 0.1.6-1+deb13u1 | ||
rpm rhel9 | - | - |
Aliases
1. 2. 3. 4. 5.