dbus_backend/ls-dbus-backend in the D-Bus backend in language-selector before 0.6.7 does not restrict access on the basis of a PolicyKit check result, which allows local users to modify the /etc/default/locale and /etc/environment files via a (1) SetSystemDefaultLangEnv or (2) SetSystemDefaultLanguageEnv call.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://launchpad.net/bugs/764397 | |
http://secunia.com/advisories/44214 | third party advisory vendor advisory |
http://www.ubuntuupdates.org/packages/show/307975 | |
https://launchpad.net/ubuntu/+source/language-selector/0.6.7 | patch |
http://www.vupen.com/english/advisories/2011/1032 | vdb entry vendor advisory |
http://www.securityfocus.com/bid/47502 | patch vdb entry |
http://www.ubuntu.com/usn/USN-1115-1/ | vendor advisory |