CVE-2013-2168
published 2013-07-03CVE-2013-2168: The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4…
PriorityP48low1.9CVSS 2.0
AVLACMAuNCNINAP
EPSS
0.38%
30.7th percentile
The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of service (service crash) via a crafted message.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dbus | < dbus 1.6.12-1 (bookworm) | dbus 1.6.12-1 (bookworm) |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | >= 0 < 1.6.12-1 | 1.6.12-1 |
| freedesktop | dbus | >= 0 < 1.6.12-1 | 1.6.12-1 |
| freedesktop | dbus | >= 0 < 1.6.12-1 | 1.6.12-1 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dbus: Crash of system services that use libdbus (DoS) due to non-portable use of va_list in UNIX format string wrapper
vendor_redhat·2013-06-13·CVSS 1.9
CVE-2013-2168 [LOW] dbus: Crash of system services that use libdbus (DoS) due to non-portable use of va_list in UNIX format string wrapper
dbus: Crash of system services that use libdbus (DoS) due to non-portable use of va_list in UNIX format string wrapper
The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of service (service crash) via a crafted message.
Statement: Not vulnerable. This issue did not affect the versions of dbus as shipped with Red Hat Enterprise Linux 5 and 6 as they did not include the upstream commit 7fc9c026669976463adcd1e02ad19c582ed27289 that introduced this issue.
Package: dbus (Red Hat Enterprise Linux 5) - Not affected
Package: dbus (Red Hat Enterprise Linux 6) - Not affected
Ubuntu
DBus vulnerability
vendor_ubuntu·2013-06-13
CVE-2013-2168 DBus vulnerability
Title: DBus vulnerability
Summary: DBus could be made to crash if it received specially crafted input.
Alexandru Cornea discovered that DBus incorrectly handled certain messages.
A local attacker could use this issue to cause system services to crash,
resulting in a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2013-2168: dbus - The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bu...
vendor_debian·2013·CVSS 1.9
CVE-2013-2168 [LOW] CVE-2013-2168: dbus - The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bu...
The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of service (service crash) via a crafted message.
Scope: local
bookworm: resolved (fixed in 1.6.12-1)
bullseye: resolved (fixed in 1.6.12-1)
forky: resolved (fixed in 1.6.12-1)
sid: resolved (fixed in 1.6.12-1)
trixie: resolved (fixed in 1.6.12-1)
GHSA
GHSA-c26p-366m-4xv6: The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix
ghsa_unreviewed·2022-05-14
CVE-2013-2168 [LOW] CWE-20 GHSA-c26p-366m-4xv6: The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix
The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of service (service crash) via a crafted message.
OSV
CVE-2013-2168: The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix
osv·2013-07-03·CVSS 1.9
CVE-2013-2168 [LOW] CVE-2013-2168: The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix
The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of service (service crash) via a crafted message.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2168 dbus: Crash of system services that use libdbus (DoS) due to non-portable use of va_list in UNIX format string wrapper [fedora-18]
bugzilla·2013-06-13·CVSS 1.9
CVE-2013-2168 [LOW] CVE-2013-2168 dbus: Crash of system services that use libdbus (DoS) due to non-portable use of va_list in UNIX format string wrapper [fedora-18]
CVE-2013-2168 dbus: Crash of system services that use libdbus (DoS) due to non-portable use of va_list in UNIX format string wrapper [fedora-18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and
Bugzilla
CVE-2013-2168 dbus: Crash of system services that use libdbus (DoS) due to non-portable use of va_list in UNIX format string wrapper
bugzilla·2013-06-13·CVSS 1.9
CVE-2013-2168 [LOW] CVE-2013-2168 dbus: Crash of system services that use libdbus (DoS) due to non-portable use of va_list in UNIX format string wrapper
CVE-2013-2168 dbus: Crash of system services that use libdbus (DoS) due to non-portable use of va_list in UNIX format string wrapper
A denial of service flaw was found in the way UNIX system D-BUS format string wrapper implementation of D-BUS, a system for sending messages between applications, used to measure the length of the provided format string and its arguments in certain circumstances. A remote attacker could supply a specially-crafted input to an application / service, utilizing the services / functionality of the libdbus library that, when processed would lead to that application / service crash.
References:
[1] http://www.openwall.com/lists/oss-security/2013/06/13/2
Relevant upstream patch:
[2] http://cgit.freedesktop.org/dbus/dbus/commit/?id=954d75b2b64e4799f360d2a6bf9cff6d9
http://cgit.freedesktop.org/dbus/dbus/commit/?id=954d75b2b64e4799f360d2a6bf9cff6d9fee37e7http://lists.fedoraproject.org/pipermail/package-announce/2013-June/109896.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/110114.htmlhttp://lists.freedesktop.org/archives/dbus/2013-June/015696.htmlhttp://lists.opensuse.org/opensuse-updates/2013-07/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00049.htmlhttp://secunia.com/advisories/53317http://secunia.com/advisories/53832http://www.debian.org/security/2013/dsa-2707http://www.mandriva.com/security/advisories?name=MDVSA-2013:177http://www.openwall.com/lists/oss-security/2013/06/13/2http://www.securityfocus.com/bid/60546http://www.securitytracker.com/id/1028667http://www.ubuntu.com/usn/USN-1874-1https://bugzilla.redhat.com/show_bug.cgi?id=974109https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16881http://cgit.freedesktop.org/dbus/dbus/commit/?id=954d75b2b64e4799f360d2a6bf9cff6d9fee37e7http://lists.fedoraproject.org/pipermail/package-announce/2013-June/109896.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/110114.htmlhttp://lists.freedesktop.org/archives/dbus/2013-June/015696.htmlhttp://lists.opensuse.org/opensuse-updates/2013-07/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00049.htmlhttp://secunia.com/advisories/53317http://secunia.com/advisories/53832http://www.debian.org/security/2013/dsa-2707http://www.mandriva.com/security/advisories?name=MDVSA-2013:177http://www.openwall.com/lists/oss-security/2013/06/13/2http://www.securityfocus.com/bid/60546http://www.securitytracker.com/id/1028667http://www.ubuntu.com/usn/USN-1874-1https://bugzilla.redhat.com/show_bug.cgi?id=974109https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16881
2013-07-03
Published