PT-2011-1152 · Freedesktop.Org+1 · D-Bus+1

Jan Lieskovsky

·

Published

2011-06-22

·

Updated

2023-12-27

·

CVE-2011-2200

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions D-Bus versions 1.2.x through 1.2.27 D-Bus versions 1.4.x through 1.4.11 D-Bus versions 1.5.x through 1.5.3
Description The issue concerns a problem with handling non-native byte order in the dbus header byteswap function, which can be exploited locally. This exploitation can lead to a denial of service, potentially sensitive information disclosure, or unspecified state-modification attacks via crafted messages.
Recommendations For D-Bus versions 1.2.x through 1.2.27, update to version 1.2.28 or later. For D-Bus versions 1.4.x through 1.4.11, update to version 1.4.12 or later. For D-Bus versions 1.5.x through 1.5.3, update to version 1.5.4 or later.

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

BDU:2015-09422
CVE-2011-2200
RHSA-2011:1132
RHSA-2011_1132

Affected Products

D-Bus
Red Hat