PT-2008-1072 · Dbus+1 · Libdbus+2
Publicado
2008-10-07
·
Atualizado
2024-06-15
·
CVE-2008-3834
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libdbus versions prior to 1.2.4
dbus versions prior to 1.2.3-r1
Description
The issue allows remote attackers to cause a denial of service via a message containing a malformed signature, which triggers a failed assertion error. Exploitation of the vulnerability can lead to disruption of confidentiality, integrity, and availability of protected information. The vulnerability can be exploited locally.
Recommendations
For libdbus versions prior to 1.2.4, update to version 1.2.4 or later to resolve the issue.
For dbus versions prior to 1.2.3-r1, update to version 1.2.3-r1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
dbus signature validate function until a patch is available.Exploit
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Dbus
Libdbus