CVE-2013-0292 describes a local privilege escalation vulnerability in the dbus_g_proxy_manager_filter function of dbus-glib before version 0.100.1, affecting freedesktop dbus-glib. An attacker can exploit this by spoofing NameOwnerChanged signals, leading to complete compromise of confidentiality, integrity, and availability. With a CVSS score of 7.2 (High), this vulnerability is considered easy to exploit locally without authentication. While not listed in CISA KEV, an exploit (EDB-33614) exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.100CPE matchmatch criteria | cpe:2.3:a:freedesktop:dbus-glib:*:*:*:*:*:*:*:* | ||
0.72CPE matchmatch criteria | cpe:2.3:a:freedesktop:dbus-glib:0.72:*:*:*:*:*:*:* | ||
0.73CPE matchmatch criteria | cpe:2.3:a:freedesktop:dbus-glib:0.73:*:*:*:*:*:*:* | ||
0.74CPE matchmatch criteria | cpe:2.3:a:freedesktop:dbus-glib:0.74:*:*:*:*:*:*:* | ||
0.76CPE matchmatch criteria | cpe:2.3:a:freedesktop:dbus-glib:0.76:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.