漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception
Vulnerability Description
xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Clients can intercept D-Bus messages they should not have access to. This vulnerability is fixed in 0.1.7.
CVSS Information
N/A
Vulnerability Type
CWE-1289
Vulnerability Title
xdg-dbus-proxy 安全漏洞
Vulnerability Description
xdg-dbus-proxy是Flatpak开源的一个D-Bus连接过滤代理。 xdg-dbus-proxy 0.1.7之前版本存在安全漏洞,该漏洞源于策略解析器未能正确处理带空格的eavesdrop属性,可能导致绕过窃听限制。
CVSS Information
N/A
Vulnerability Type
N/A