PT-2014-1923 · D-Bus+2 · Dbus+2

Publicado

2014-07-02

·

Atualizado

2024-06-15

·

CVE-2014-3533

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dbus versions 1.3.0 through 1.6.22 dbus versions 1.8.x through 1.8.6 dbus versions prior to 1.8.10
Description The issue allows local users to cause a denial of service (disconnect) via a certain sequence of crafted messages that cause the dbus-daemon to forward a message containing an invalid file descriptor. Multiple vulnerabilities in the dbus package can lead to violations of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be carried out remotely.
Recommendations For dbus versions 1.3.0 through 1.6.22, update to version 1.6.22 or later. For dbus versions 1.8.x through 1.8.6, update to version 1.8.6 or later. For dbus versions prior to 1.8.10, update to version 1.8.10 or later.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1893
BDU:2015-09788
CVE-2014-3533
DSA-2971-1
MGASA-2014-0294
OPENSUSE-SU-2024:10517-1
USN-2275-1

Produtos afetados

Alt Linux
Ubuntu
Dbus