PT-2008-1072 · Dbus+1 · Libdbus+2

Publicado

2008-10-07

·

Atualizado

2024-06-15

·

CVE-2008-3834

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libdbus versions prior to 1.2.4 dbus versions prior to 1.2.3-r1
Description The issue allows remote attackers to cause a denial of service via a message containing a malformed signature, which triggers a failed assertion error. Exploitation of the vulnerability can lead to disruption of confidentiality, integrity, and availability of protected information. The vulnerability can be exploited locally.
Recommendations For libdbus versions prior to 1.2.4, update to version 1.2.4 or later to resolve the issue. For dbus versions prior to 1.2.3-r1, update to version 1.2.3-r1 or later to resolve the issue. As a temporary workaround, consider restricting access to the dbus signature validate function until a patch is available.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06719
BDU:2015-06723
BDU:2015-06735
BDU:2015-08450
BDU:2015-08451
BDU:2015-08452
BDU:2015-09355
CVE-2008-3834
DSA-1658-1
OPENSUSE-SU-2024:10711-1
RHSA-2009:0008
RHSA-2009_0008

Produtos afetados

Red Hat
Dbus
Libdbus