CVE-2006-6107
published 2006-12-14CVE-2006-6107: Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other…
PriorityP46low1.7CVSS 2.0
AVLACLAuSCNINAP
EPSS
0.38%
29.9th percentile
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-bus | d-bus | — | — |
| d-bus | d-bus | — | — |
| d-bus | d-bus | — | — |
| d-bus | d-bus | — | — |
| d-bus | d-bus | — | — |
| d-bus | d-bus | — | — |
| d-bus | d-bus | — | — |
| debian | dbus | < dbus 1.0.2-1 (bookworm) | dbus 1.0.2-1 (bookworm) |
| freedesktop | dbus | >= 0 < 1.0.2-1 | 1.0.2-1 |
| freedesktop | dbus | >= 0 < 1.0.2-1 | 1.0.2-1 |
| freedesktop | dbus | >= 0 < 1.0.2-1 | 1.0.2-1 |
| freedesktop | dbus | >= 0 < 1.0.2-1 | 1.0.2-1 |
CVSS provenance
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
osv1.7LOW
vendor_debian1.7LOW
vendor_redhat1.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
D-Bus vulnerability
vendor_ubuntu·2007-01-04
CVE-2006-6107 D-Bus vulnerability
Title: D-Bus vulnerability
Summary: D-Bus vulnerability
Kimmo Hämäläinen discovered that local users could delete other users'
D-Bus match rules. Applications would stop receiving D-Bus messages,
resulting in a local denial of service, and potential data loss for
applications that depended on D-Bus for storing information.
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Red Hat
D-Bus denial of service
vendor_redhat·2006-12-12·CVSS 1.7
CVE-2006-6107 [LOW] D-Bus denial of service
D-Bus denial of service
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2006-6107: dbus - Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D...
vendor_debian·2006·CVSS 1.7
CVE-2006-6107 [LOW] CVE-2006-6107: dbus - Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D...
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).
Scope: local
bookworm: resolved (fixed in 1.0.2-1)
bullseye: resolved (fixed in 1.0.2-1)
forky: resolved (fixed in 1.0.2-1)
sid: resolved (fixed in 1.0.2-1)
trixie: resolved (fixed in 1.0.2-1)
GHSA
GHSA-r8m2-5wq2-xvh3: Unspecified vulnerability in the match_rule_equal function in bus/signals
ghsa_unreviewed·2022-05-01
CVE-2006-6107 [LOW] GHSA-r8m2-5wq2-xvh3: Unspecified vulnerability in the match_rule_equal function in bus/signals
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).
OSV
CVE-2006-6107: Unspecified vulnerability in the match_rule_equal function in bus/signals
osv·2006-12-14·CVSS 1.7
CVE-2006-6107 [LOW] CVE-2006-6107: Unspecified vulnerability in the match_rule_equal function in bus/signals
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-6107 D-Bus denial of service
bugzilla·2006-12-14·CVSS 1.7
CVE-2006-6107 [LOW] CVE-2006-6107 D-Bus denial of service
CVE-2006-6107 D-Bus denial of service
+++ This bug was initially created as a clone of Bug #218055 +++
Kimmo Hämäläinen reported a DoS flaw in D-Bus to the freedesktop.org
bugzilla. To quote his bug:
I found a nasty bug from match_rule_equal() that can cause matches
to be removed from another connections (thanks goes to other guys
for finding reproducable use case for the bug).
This flaw can cause a local user to disable the the ability of another
process to receive certain messages. This flaw does not contain any
potential for arbitrary code execution. Here is a more details description
from Kimmo:
We don't have the software public yet, but the use case was the
following. There are three processes A, B, and C. All of them add
the same match (same value). A is started first, then B, a
Bugzilla
CVE-2006-6107 D-Bus denial of service
bugzilla·2006-12-01·CVSS 1.7
CVE-2006-6107 [LOW] CVE-2006-6107 D-Bus denial of service
CVE-2006-6107 D-Bus denial of service
Kimmo Hämäläinen reported a DoS flaw in D-Bus to the freedesktop.org
bugzilla. To quote his bug:
I found a nasty bug from match_rule_equal() that can cause matches
to be removed from another connections (thanks goes to other guys
for finding reproducable use case for the bug).
This flaw can cause a local user to disable the the ability of another
process to receive certain messages. This flaw does not contain any
potential for arbitrary code execution. Here is a more details description
from Kimmo:
We don't have the software public yet, but the use case was the
following. There are three processes A, B, and C. All of them add
the same match (same value). A is started first, then B, and lastly
C. Now, B and C are closed: if B is closed before C, A's
http://archives.mandrivalinux.com/security-announce/2006-12/msg00025.phphttp://lists.opensuse.org/opensuse-updates/2012-10/msg00094.htmlhttp://lists.rpath.com/pipermail/security-announce/2007-February/000147.htmlhttp://openpkg.com/go/OpenPKG-SA-2006.041http://secunia.com/advisories/23373http://secunia.com/advisories/23390http://secunia.com/advisories/23611http://secunia.com/advisories/24059http://secunia.com/advisories/24131http://www.freedesktop.org/wiki/Software/dbushttp://www.redhat.com/support/errata/RHSA-2007-0008.htmlhttp://www.securityfocus.com/bid/21571http://www.securitytracker.com/id?1017608http://www.ubuntu.com/usn/usn-401-1http://www.vupen.com/english/advisories/2006/4988https://bugs.freedesktop.org/show_bug.cgi?id=9142https://exchange.xforce.ibmcloud.com/vulnerabilities/30874https://issues.rpath.com/browse/RPL-860https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9951http://archives.mandrivalinux.com/security-announce/2006-12/msg00025.phphttp://lists.opensuse.org/opensuse-updates/2012-10/msg00094.htmlhttp://lists.rpath.com/pipermail/security-announce/2007-February/000147.htmlhttp://openpkg.com/go/OpenPKG-SA-2006.041http://secunia.com/advisories/23373http://secunia.com/advisories/23390http://secunia.com/advisories/23611http://secunia.com/advisories/24059http://secunia.com/advisories/24131http://www.freedesktop.org/wiki/Software/dbushttp://www.redhat.com/support/errata/RHSA-2007-0008.htmlhttp://www.securityfocus.com/bid/21571http://www.securitytracker.com/id?1017608http://www.ubuntu.com/usn/usn-401-1http://www.vupen.com/english/advisories/2006/4988https://bugs.freedesktop.org/show_bug.cgi?id=9142https://exchange.xforce.ibmcloud.com/vulnerabilities/30874https://issues.rpath.com/browse/RPL-860https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9951
2006-12-14
Published