PT-2014-1921 · Freedesktop.Org+3 · D-Bus+3

Published

2014-06-18

·

Updated

2025-01-16

·

CVE-2014-3477

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions D-Bus versions 1.2.x through 1.4.x D-Bus versions 1.6.x before 1.6.20 D-Bus versions 1.8.x before 1.8.10
Description The issue allows local users to cause a denial of service or possibly conduct a side-channel attack via a D-Bus message to an inactive service. This occurs because the dbus-daemon sends an AccessDenied error to the service instead of the client when access is prohibited. Exploitation of the vulnerabilities may lead to disruption of confidentiality, integrity, and availability of protected information and can be performed remotely.
Recommendations For D-Bus versions 1.2.x through 1.4.x, update to a version after 1.4.x. For D-Bus versions 1.6.x before 1.6.20, update to version 1.6.20 or later. For D-Bus versions 1.8.x before 1.8.10, update to version 1.8.10 or later.

Fix

Related Identifiers

ALT-PU-2014-1798
BDU:2015-09788
CVE-2014-3477
DLA-87-1
DSA-2971-1
MGASA-2014-0266
OPENSUSE-SU-2024:10517-1
SUSE-SU-2014_0846-1
USN-2275-1

Affected Products

Alt Linux
D-Bus
Suse
Ubuntu