PT-2014-1922 · D-Bus+1 · Dbus+1

Published

2014-07-02

·

Updated

2024-06-15

·

CVE-2014-3532

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dbus versions 1.3.0 through 1.6.22 dbus versions 1.8.x through 1.8.6
Description The issue allows local users to cause a denial of service by sending a message containing a file descriptor and then exceeding the maximum recursion depth before the initial message is forwarded. This can lead to a system-bus disconnect of other services or applications. Additionally, there are multiple vulnerabilities in the dbus package that can lead to violations of confidentiality, integrity, and availability of protected information, potentially exploitable remotely.
Recommendations For dbus versions 1.3.0 through 1.6.22, update to version 1.6.22 or later. For dbus versions 1.8.x through 1.8.6, update to version 1.8.6 or later. As a temporary workaround, consider restricting access to the system bus to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09788
CVE-2014-3532
DSA-2971-1
MGASA-2014-0294
OPENSUSE-SU-2024:10517-1
USN-2275-1

Affected Products

Ubuntu
Dbus