CVE-2010-4352Project D-bus vulnerability

CWE-3998 documents8 sources
Severity
2.1LOWNVD
EPSS
0.1%
top 72.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30
Latest updateMay 17

Description

Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants.

CVSS vector

AV:L/AC:L/C:N/I:N/A:PExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

Debianfreedesktop/dbus< 1.2.24-4+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-47vh-r2fv-pgcx: Stack consumption vulnerability in D-Bus (aka DBus) before 12022-05-17
OSV
CVE-2010-4352: Stack consumption vulnerability in D-Bus (aka DBus) before 12010-12-30
CVEList
CVE-2010-4352: Stack consumption vulnerability in D-Bus (aka DBus) before 12010-12-30

📋Vendor Advisories

3
Ubuntu
D-Bus vulnerability2011-01-18
Red Hat
D-BUS: Stack overflow by validating message with excessive number of nested variants2010-12-11
Debian
CVE-2010-4352: dbus - Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local us...2010

💬Community

1
Bugzilla
CVE-2010-4352 D-BUS: Stack overflow by validating message with excessive number of nested variants2010-12-16