Linux Blueman D-Bus Service EnableNetwork Privilege Escalation Exploit

The EnableNetwork method in the org.blueman.Mechanism D-Bus service of Blueman, a Bluetooth Manager, receives untrusted Python code provided by unprivileged users and evaluates it as root. This can be leveraged by a local unprivileged attacker to gain root privileges.
Monday, January 18, 2016 - 00:00