PT-2014-9098 · Freedesktop.Org+3 · D-Bus+3

Alban Crequy

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2014-3638

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions D-Bus versions prior to 1.6.24 D-Bus versions 1.8.x prior to 1.8.8 dbus-1 versions (affected versions not specified) dbus-1-32bit versions (affected versions not specified) dbus-1-x11 versions (affected versions not specified) dbus-1-devel-doc versions (affected versions not specified) dbus-1-devel versions (affected versions not specified)
Description The issue allows local users to cause a denial of service (CPU consumption) via a large number of method calls, potentially leading to disruption of protected information. This can be exploited locally. The bus connections check reply function in config-parser.c is specifically vulnerable.
Recommendations For D-Bus versions prior to 1.6.24, update to version 1.6.24 or later. For D-Bus versions 1.8.x prior to 1.8.8, update to version 1.8.8 or later. For dbus-1, dbus-1-32bit, dbus-1-x11, dbus-1-devel-doc, and dbus-1-devel, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2148
BDU:2015-04278
BDU:2015-04279
BDU:2015-04280
BDU:2015-04281
BDU:2015-04282
BDU:2015-09788
CVE-2014-3638
DLA-87-1
DSA-3026-1
MGASA-2014-0395
OPENSUSE-SU-2024:10517-1
SUSE-SU-2014_1146-1
USN-2352-1

Affected Products

Alt Linux
D-Bus
Suse
Ubuntu