PT-2014-1922 · D-Bus+1 · Dbus+1

Publicado

2014-07-02

·

Atualizado

2024-06-15

·

CVE-2014-3532

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dbus versions 1.3.0 through 1.6.22 dbus versions 1.8.x through 1.8.6
Description The issue allows local users to cause a denial of service by sending a message containing a file descriptor and then exceeding the maximum recursion depth before the initial message is forwarded. This can lead to a system-bus disconnect of other services or applications. Additionally, there are multiple vulnerabilities in the dbus package that can lead to violations of confidentiality, integrity, and availability of protected information, potentially exploitable remotely.
Recommendations For dbus versions 1.3.0 through 1.6.22, update to version 1.6.22 or later. For dbus versions 1.8.x through 1.8.6, update to version 1.8.6 or later. As a temporary workaround, consider restricting access to the system bus to minimize the risk of exploitation.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09788
CVE-2014-3532
DSA-2971-1
MGASA-2014-0294
OPENSUSE-SU-2024:10517-1
USN-2275-1

Produtos afetados

Ubuntu
Dbus