PT-2014-1923 · D-Bus+2 · Dbus+2

Published

2014-07-02

·

Updated

2024-06-15

·

CVE-2014-3533

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dbus versions 1.3.0 through 1.6.22 dbus versions 1.8.x through 1.8.6 dbus versions prior to 1.8.10
Description The issue allows local users to cause a denial of service (disconnect) via a certain sequence of crafted messages that cause the dbus-daemon to forward a message containing an invalid file descriptor. Multiple vulnerabilities in the dbus package can lead to violations of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be carried out remotely.
Recommendations For dbus versions 1.3.0 through 1.6.22, update to version 1.6.22 or later. For dbus versions 1.8.x through 1.8.6, update to version 1.8.6 or later. For dbus versions prior to 1.8.10, update to version 1.8.10 or later.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1893
BDU:2015-09788
CVE-2014-3533
DSA-2971-1
MGASA-2014-0294
OPENSUSE-SU-2024:10517-1
USN-2275-1

Affected Products

Alt Linux
Ubuntu
Dbus