PT-2008-1072 · Dbus+1 · Libdbus+2

Published

2008-10-07

·

Updated

2024-06-15

·

CVE-2008-3834

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libdbus versions prior to 1.2.4 dbus versions prior to 1.2.3-r1
Description The issue allows remote attackers to cause a denial of service via a message containing a malformed signature, which triggers a failed assertion error. Exploitation of the vulnerability can lead to disruption of confidentiality, integrity, and availability of protected information. The vulnerability can be exploited locally.
Recommendations For libdbus versions prior to 1.2.4, update to version 1.2.4 or later to resolve the issue. For dbus versions prior to 1.2.3-r1, update to version 1.2.3-r1 or later to resolve the issue. As a temporary workaround, consider restricting access to the dbus signature validate function until a patch is available.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06719
BDU:2015-06723
BDU:2015-06735
BDU:2015-08450
BDU:2015-08451
BDU:2015-08452
BDU:2015-09355
CVE-2008-3834
DSA-1658-1
OPENSUSE-SU-2024:10711-1
RHSA-2009:0008
RHSA-2009_0008

Affected Products

Red Hat
Dbus
Libdbus