PT-2008-1072 · Dbus+1 · Libdbus+2
Published
2008-10-07
·
Updated
2024-06-15
·
CVE-2008-3834
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libdbus versions prior to 1.2.4
dbus versions prior to 1.2.3-r1
Description
The issue allows remote attackers to cause a denial of service via a message containing a malformed signature, which triggers a failed assertion error. Exploitation of the vulnerability can lead to disruption of confidentiality, integrity, and availability of protected information. The vulnerability can be exploited locally.
Recommendations
For libdbus versions prior to 1.2.4, update to version 1.2.4 or later to resolve the issue.
For dbus versions prior to 1.2.3-r1, update to version 1.2.3-r1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
dbus signature validate function until a patch is available.Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Dbus
Libdbus