CVE-2008-3834
published 2008-10-07CVE-2008-3834: The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a…
PriorityP414low2.1CVSS 2.0
AVLACLAuNCNINAP
EXPLOIT
EPSS
4.62%
90.7th percentile
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dbus | < dbus 1.2.14-1 (bookworm) | dbus 1.2.14-1 (bookworm) |
| debian | dbus | < dbus 1.2.1-4 (bookworm) | dbus 1.2.1-4 (bookworm) |
| freedesktop | dbus | <= 1.2.3 | — |
| freedesktop | dbus | <= 1.1.4 | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_ubuntu4.6MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dbus: invalid signatures verified as valid due to improper fix for CVE-2008-3834
vendor_redhat·2015-02-06·CVSS 2.1
CVE-2009-1193 [LOW] dbus: invalid signatures verified as valid due to improper fix for CVE-2008-3834
dbus: invalid signatures verified as valid due to improper fix for CVE-2008-3834
No description is available for this CVE.
Red Hat
dbus: invalid fix for CVE-2008-3834
vendor_redhat·2009-04-16·CVSS 2.1
CVE-2009-1189 [LOW] dbus: invalid fix for CVE-2008-3834
dbus: invalid fix for CVE-2008-3834
The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.
Debian
CVE-2009-1189: dbus - The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D...
vendor_debian·2009·CVSS 2.1
CVE-2009-1189 [LOW] CVE-2009-1189: dbus - The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D...
The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.
Scope: local
bookworm: resolved (fixed in 1.2.14-1)
bullseye: resolved (fixed in 1.2.14-1)
forky: resolved (fixed in 1.2.14-1)
sid: resolved (fixed in 1.2.14-1)
trixie: resolved (fixed in 1.2.14-1)
Ubuntu
D-Bus vulnerabilities
vendor_ubuntu·2008-10-14·CVSS 4.6
CVE-2008-0595 [MEDIUM] D-Bus vulnerabilities
Title: D-Bus vulnerabilities
Summary: D-Bus vulnerabilities
Havoc Pennington discovered that the D-Bus daemon did not correctly
validate certain security policies. If a local user sent a specially
crafted D-Bus request, they could bypass security policies that had a
"send_interface" defined. (CVE-2008-0595)
It was discovered that the D-Bus library did not correctly validate
certain corrupted signatures. If a local user sent a specially crafted
D-Bus request, they could crash applications linked against the D-Bus
library, leading to a denial of service. (CVE-2008-3834)
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Red Hat
dbus denial of service
vendor_redhat·2008-09-27·CVSS 2.1
CVE-2008-3834 [LOW] dbus denial of service
dbus denial of service
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.
Debian
CVE-2008-3834: dbus - The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4...
vendor_debian·2008·CVSS 2.1
CVE-2008-3834 [LOW] CVE-2008-3834: dbus - The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4...
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.
Scope: local
bookworm: resolved (fixed in 1.2.1-4)
bullseye: resolved (fixed in 1.2.1-4)
forky: resolved (fixed in 1.2.1-4)
sid: resolved (fixed in 1.2.1-4)
trixie: resolved (fixed in 1.2.1-4)
GHSA
GHSA-mwh5-h5c7-v5xw: The dbus_signature_validate function in the D-bus library (libdbus) before 1
ghsa_unreviewed·2022-05-02
CVE-2008-3834 [LOW] CWE-20 GHSA-mwh5-h5c7-v5xw: The dbus_signature_validate function in the D-bus library (libdbus) before 1
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.
GHSA
GHSA-2332-hcww-wjmr: The _dbus_validate_signature_with_reason function (dbus-marshal-validate
ghsa_unreviewed·2022-05-02·CVSS 2.1
CVE-2009-1189 [LOW] CWE-20 GHSA-2332-hcww-wjmr: The _dbus_validate_signature_with_reason function (dbus-marshal-validate
The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.
OSV
CVE-2009-1189: The _dbus_validate_signature_with_reason function (dbus-marshal-validate
osv·2009-04-27·CVSS 2.1
CVE-2009-1189 [LOW] CVE-2009-1189: The _dbus_validate_signature_with_reason function (dbus-marshal-validate
The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.
OSV
CVE-2008-3834: The dbus_signature_validate function in the D-bus library (libdbus) before 1
osv·2008-10-07·CVSS 2.1
CVE-2008-3834 [LOW] CVE-2008-3834: The dbus_signature_validate function in the D-bus library (libdbus) before 1
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.
No detection rules found.
Bugzilla
CVE-2009-1193 dbus: invalid signatures verified as valid due to improper fix for CVE-2008-3834
bugzilla·2009-04-22·CVSS 2.1
CVE-2009-1193 [LOW] CVE-2009-1193 dbus: invalid signatures verified as valid due to improper fix for CVE-2008-3834
CVE-2009-1193 dbus: invalid signatures verified as valid due to improper fix for CVE-2008-3834
The patch used to correct CVE-2008-3834 caused a new issue in dbus where it would verify invalid signatures as valid. This flaw would only affect dbus 1.2.4
and higher, or any dbus packages that applied the original upstream patch to correct CVE-2008-3834.
Discussion:
(In reply to comment #3)
> (In reply to comment #2)
> > Access Complexity: High (no existing applications will act on an invalid
> > signature so this would need to be custom/unsupported app that is written
> > incorrectly)
>
> Not sure if this is reason for AC:H. When scoring, you need to assume worst
> case - i.e. if there is an application that does something with invalid
> signatures and assess difficulty of triggering mis-be
Bugzilla
CVE-2009-1189 dbus: invalid fix for CVE-2008-3834
bugzilla·2009-04-20·CVSS 2.1
CVE-2009-1189 [LOW] CVE-2009-1189 dbus: invalid fix for CVE-2008-3834
CVE-2009-1189 dbus: invalid fix for CVE-2008-3834
It was found that the patch to fix CVE-2008-3834 in dbus was incorrect and as a
result the flaw was never properly fixed (remote denial of service
vulnerability). This issue has been assigned CVE-2009-1189.
The upstream bug report is here:
https://bugs.freedesktop.org/show_bug.cgi?id=17803
Our bug report for CVE-2008-3834 is bug #464674 .
Discussion:
The upstream fix is here:
https://bugs.freedesktop.org/attachment.cgi?id=24436
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0018 https://rhn.redhat.com/errata/RHSA-2010-0018.html
Bugzilla
CVE-2008-3834 dbus denial of service
bugzilla·2008-09-29·CVSS 2.1
CVE-2008-3834 [LOW] CVE-2008-3834 dbus denial of service
CVE-2008-3834 dbus denial of service
Upstream bug report:
https://bugs.freedesktop.org/show_bug.cgi?id=17803
It is likely possible to send a message with a malformed signature which would cause the bus (or in general any process using libdbus to receive messages) to abort.
Discussion:
Do you know what versions of dbus are affected by this?
---
This code dates at least as far back as:
commit 5e389fdf499c39926c61b47fcafb5e71291ce1a2
Author: John (J5) Palmieri
Date: Wed Jun 15 15:15:32 2005 +0000
---
According to brew the first build of dbus in RHEL is 2006, so I think this affects both EL4 and EL5. Does not affect EL3 or earlier as I don't believe DBus is shipped there.
---
By the way I could use some hand-holding with respect to how this should be handled upstream, things like i
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00094.htmlhttp://secunia.com/advisories/32127http://secunia.com/advisories/32230http://secunia.com/advisories/32281http://secunia.com/advisories/32385http://secunia.com/advisories/33396http://www.debian.org/security/2008/dsa-1658http://www.freedesktop.org/wiki/Software/dbus#head-dad0dab297a44f1d7a3b1259cfc06b583fd6a88ahttp://www.mandriva.com/security/advisories?name=MDVSA-2008:213http://www.redhat.com/support/errata/RHSA-2009-0008.htmlhttp://www.securityfocus.com/bid/31602http://www.securitytracker.com/id?1021063http://www.ubuntu.com/usn/usn-653-1http://www.vupen.com/english/advisories/2008/2762https://bugs.freedesktop.org/show_bug.cgi?id=17803https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-3834https://exchange.xforce.ibmcloud.com/vulnerabilities/45701https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10253https://www.exploit-db.com/exploits/7822https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00298.htmlhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00094.htmlhttp://secunia.com/advisories/32127http://secunia.com/advisories/32230http://secunia.com/advisories/32281http://secunia.com/advisories/32385http://secunia.com/advisories/33396http://www.debian.org/security/2008/dsa-1658http://www.freedesktop.org/wiki/Software/dbus#head-dad0dab297a44f1d7a3b1259cfc06b583fd6a88ahttp://www.mandriva.com/security/advisories?name=MDVSA-2008:213http://www.redhat.com/support/errata/RHSA-2009-0008.htmlhttp://www.securityfocus.com/bid/31602http://www.securitytracker.com/id?1021063http://www.ubuntu.com/usn/usn-653-1http://www.vupen.com/english/advisories/2008/2762https://bugs.freedesktop.org/show_bug.cgi?id=17803https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-3834https://exchange.xforce.ibmcloud.com/vulnerabilities/45701https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10253https://www.exploit-db.com/exploits/7822https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00298.html
2008-10-07
Published