PT-2011-1152 · Freedesktop.Org+1 · D-Bus+1
Jan Lieskovsky
·
Published
2011-06-22
·
Updated
2023-12-27
·
CVE-2011-2200
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
D-Bus versions 1.2.x through 1.2.27
D-Bus versions 1.4.x through 1.4.11
D-Bus versions 1.5.x through 1.5.3
Description
The issue concerns a problem with handling non-native byte order in the
dbus header byteswap function, which can be exploited locally. This exploitation can lead to a denial of service, potentially sensitive information disclosure, or unspecified state-modification attacks via crafted messages.Recommendations
For D-Bus versions 1.2.x through 1.2.27, update to version 1.2.28 or later.
For D-Bus versions 1.4.x through 1.4.11, update to version 1.4.12 or later.
For D-Bus versions 1.5.x through 1.5.3, update to version 1.5.4 or later.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Bus
Red Hat