Improper Verification of Source of a Communication Channel Affecting linuxdeepin/dde-api-proxy package, versions [0,]


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-LINUXDEEPINDDEAPIPROXY-8663241
  • published26 Jan 2025
  • disclosed24 Jan 2025
  • creditUnknown

Introduced: 24 Jan 2025

NewCVE-2025-23222  (opens in a new tab)
CWE-940  (opens in a new tab)

How to fix?

There is no fixed version for linuxdeepin/dde-api-proxy.

Overview

Affected versions of this package are vulnerable to Improper Verification of Source of a Communication Channel due to improper D-Bus message handling. An attacker can escalate privileges and execute actions as root by sending crafted messages to D-Bus services, which mistakenly trust the proxy's root identity.

Note: This vulnerability was partially fixed in 1.0.19

CVSS Scores

version 4.0
version 3.1