157 lines
5.3 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2009-0489",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-02-09T20:30:02.767",
"lastModified": "2012-07-02T04:00:00.000",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "The DBus configuration file for Wicd before 1.5.9 allows arbitrary users to own org.wicd.daemon, which allows local users to receive messages that were intended for the Wicd daemon, possibly including credentials."
},
{
"lang": "es",
"value": "El fichero de configuraci\u00f3n DBus de Wicd anteriores a v1.5.9 permite a cualquier usuario tomar posesi\u00f3n del fichero org.wicd.daemon, lo que permite a usuarios locales recibir mensajes que estaban destinados al demonio Wicd, posiblemente incluso credenciales."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 2.1
},
"baseSeverity": "LOW",
"exploitabilityScore": 3.9,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-16"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.5.8",
"matchCriteriaId": "DA9F8B78-6C51-4F0C-965E-831C81977BFE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:1.2.7:*:*:*:*:*:*:*",
"matchCriteriaId": "06AFC460-E683-4047-8C2A-1E9AC377917B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:1.3.1:*:*:*:*:*:*:*",
"matchCriteriaId": "A2D411ED-67BF-45A0-BE8A-E981CAB0F4CD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:1.4.0:*:*:*:*:*:*:*",
"matchCriteriaId": "45632B83-B5C7-42AC-9B8B-031AB0D6417A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:1.4.1:*:*:*:*:*:*:*",
"matchCriteriaId": "52DCBA8B-FD94-4184-985A-E054DEC04671"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:1.4.2:*:*:*:*:*:*:*",
"matchCriteriaId": "9F48E42D-AEEA-41EC-BCFB-5581CEA05B58"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:1.5.0:*:*:*:*:*:*:*",
"matchCriteriaId": "288E7A59-D1BA-45D7-A30A-9F5F56E5A192"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:1.5.1:*:*:*:*:*:*:*",
"matchCriteriaId": "2265EFEA-CEF9-42E0-A538-8D8FAE5F351C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:1.5.2:*:*:*:*:*:*:*",
"matchCriteriaId": "7769F3E0-EF1A-480C-845E-7178F2939ECD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:1.5.3:*:*:*:*:*:*:*",
"matchCriteriaId": "22A39899-C5D7-47D0-9B9C-6ADD1F756B46"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:1.5.4:*:*:*:*:*:*:*",
"matchCriteriaId": "27ED667E-BD1E-4352-A5F0-DB70B86D600D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:1.5.5:*:*:*:*:*:*:*",
"matchCriteriaId": "84B74048-746F-4DF7-913D-3F0163FC8FD1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:1.5.6:*:*:*:*:*:*:*",
"matchCriteriaId": "F9E268AD-D2A5-48DD-A311-6C2CD8A67149"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:david_paleino:wicd:1.5.7:*:*:*:*:*:*:*",
"matchCriteriaId": "D5FE6B55-58EA-403E-AA60-2079A559D2CB"
}
]
}
]
}
],
"references": [
{
"url": "http://bazaar.launchpad.net/~wicd-devel/wicd/trunk/revision/222",
"source": "cve@mitre.org"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200904-12.xml",
"source": "cve@mitre.org"
},
{
"url": "http://sourceforge.net/project/shownotes.php?group_id=194573&release_id=659059",
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2009/02/06/4",
"source": "cve@mitre.org"
}
]
}