The DBus configuration file for Wicd before 1.5.9 allows arbitrary users to own org.wicd.daemon, which allows local users to receive messages that were intended for the Wicd daemon, possibly including credentials.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
http://security.gentoo.org/glsa/glsa-200904-12.xml | vendor advisory |
http://secunia.com/advisories/34685 | third party advisory |
http://sourceforge.net/project/shownotes.php?group_id=194573&release_id=659059 | |
http://www.openwall.com/lists/oss-security/2009/02/06/4 | mailing list |
http://secunia.com/advisories/33870 | third party advisory |
http://bazaar.launchpad.net/~wicd-devel/wicd/trunk/revision/222 |