CVE-2010-1172
Title: Freedesktop Dbus-Glib Denial of Service (DoS)
DoS
Proof Of Concept
No public PoC currently indexed for CVE-2010-1172.
CWE Category
CWE-264
Published Date
Aug 20, 2010
Modified Date
Apr 29, 2026
Exploit Status
Not Found
Score
3.6
CVSS v2.0
Exploit Probability (EPSS)
0.07%
Vulnerability Summary
CVE-2010-1172: DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services.
Impacted Vendors
Reference Links
http://cgit.freedesktop.org/dbus/dbus-glib/commit/?h=rhel5&id=9a6bce9b615abca6068348c1606ba8eaf13d9ae0
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00006.html
http://secunia.com/advisories/40908
http://secunia.com/advisories/40925
http://secunia.com/advisories/42397
http://support.avaya.com/css/P8/documents/100113103
http://www.redhat.com/support/errata/RHSA-2010-0616.html
http://www.securityfocus.com/bid/42347
http://www.vupen.com/english/advisories/2010/2063
http://www.vupen.com/english/advisories/2010/3097
https://bugzilla.redhat.com/show_bug.cgi?id=585394
https://exchange.xforce.ibmcloud.com/vulnerabilities/61041
http://cgit.freedesktop.org/dbus/dbus-glib/commit/?h=rhel5&id=9a6bce9b615abca6068348c1606ba8eaf13d9ae0
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00006.html
http://secunia.com/advisories/40908
http://secunia.com/advisories/40925
http://secunia.com/advisories/42397
http://support.avaya.com/css/P8/documents/100113103
http://www.redhat.com/support/errata/RHSA-2010-0616.html
http://www.securityfocus.com/bid/42347
http://www.vupen.com/english/advisories/2010/2063
http://www.vupen.com/english/advisories/2010/3097
https://bugzilla.redhat.com/show_bug.cgi?id=585394
https://exchange.xforce.ibmcloud.com/vulnerabilities/61041
CVSS v2.0
Source Entity
[email protected]
Severity
LOW
3.6
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:L/AC:L/Au:N/C:N/I:P/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2010-1172 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:L/AC:L/Au:N/C:N/I:P/A:P
Affected Stack
No specific products linked.