CVE-2014-3477
published 2014-07-01CVE-2014-3477: The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when…
PriorityP411medium4CVSS 3.1
AVLACLPRNUINSUCNINAL
EPSS
0.44%
36.0th percentile
The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D-Bus message to an inactive service.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-bus_project | d-bus | — | — |
| d-bus_project | d-bus | — | — |
| d-bus_project | d-bus | — | — |
| debian | dbus | < dbus 1.8.4-1 (bookworm) | dbus 1.8.4-1 (bookworm) |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
CVSS provenance
nvdv3.14.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv4.0MEDIUM
vendor_debian4.0LOW
vendor_redhat4.0MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
DBus vulnerabilities
vendor_ubuntu·2014-07-08·CVSS 4.0
CVE-2014-3477 [MEDIUM] DBus vulnerabilities
Title: DBus vulnerabilities
Summary: Several security issues were fixed in DBus.
Alban Crequy discovered that dbus-daemon incorrectly sent AccessDenied
errors to the service instead of the client when enforcing permissions. A
local user can use this issue to possibly deny access to the service.
(CVE-2014-3477)
Alban Crequy discovered that dbus-daemon incorrectly handled certain file
descriptors. A local attacker could use this issue to cause services or
clients to disconnect, resulting in a denial of service. (CVE-2014-3532,
CVE-2014-3533)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
dbus: denial of service flaw in dbus-daemon
vendor_redhat·2014-06-10·CVSS 4.0
CVE-2014-3477 [MEDIUM] dbus: denial of service flaw in dbus-daemon
dbus: denial of service flaw in dbus-daemon
The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D-Bus message to an inactive service.
Statement: This issue affect the dbus package in Red Hat Enterprise Linux 5, 6, 7. Red Hat Product Security has rated this issue as having Moderate security impact, a future update my address this flaw in Red Hat Enterprise Linux 6 and 7. This issue is not planned to be fixed in Red Hat Enterprise Linux 5 as it is now in Production 3 Phase of the support and mainten
Debian
CVE-2014-3477: dbus - The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x bef...
vendor_debian·2014·CVSS 4.0
CVE-2014-3477 [MEDIUM] CVE-2014-3477: dbus - The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x bef...
The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D-Bus message to an inactive service.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1.8.4-1)
trixie: resolved (fixed in 1.8.4-1)
GHSA
GHSA-qj2p-fqqf-6x63: The dbus-daemon in D-Bus 1
ghsa_unreviewed·2022-05-17
CVE-2014-3477 [LOW] GHSA-qj2p-fqqf-6x63: The dbus-daemon in D-Bus 1
The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D-Bus message to an inactive service.
OSV
dbus vulnerabilities
osv·2014-07-08·CVSS 4.0
CVE-2014-3477 [MEDIUM] dbus vulnerabilities
dbus vulnerabilities
Alban Crequy discovered that dbus-daemon incorrectly sent AccessDenied
errors to the service instead of the client when enforcing permissions. A
local user can use this issue to possibly deny access to the service.
(CVE-2014-3477)
Alban Crequy discovered that dbus-daemon incorrectly handled certain file
descriptors. A local attacker could use this issue to cause services or
clients to disconnect, resulting in a denial of service. (CVE-2014-3532,
CVE-2014-3533)
OSV
CVE-2014-3477: The dbus-daemon in D-Bus 1
osv·2014-07-01·CVSS 4.0
CVE-2014-3477 [MEDIUM] CVE-2014-3477: The dbus-daemon in D-Bus 1
The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D-Bus message to an inactive service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3477 mingw-dbus: dbus: denial of service flaw in dbus-daemon [fedora-all]
bugzilla·2014-07-08·CVSS 4.0
CVE-2014-3477 [MEDIUM] CVE-2014-3477 mingw-dbus: dbus: denial of service flaw in dbus-daemon [fedora-all]
CVE-2014-3477 mingw-dbus: dbus: denial of service flaw in dbus-daemon [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects mult
Bugzilla
CVE-2014-3477 dbus: denial of service flaw in dbus-daemon [fedora-all]
bugzilla·2014-06-11·CVSS 4.0
CVE-2014-3477 [MEDIUM] CVE-2014-3477 dbus: denial of service flaw in dbus-daemon [fedora-all]
CVE-2014-3477 dbus: denial of service flaw in dbus-daemon [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple support
Bugzilla
CVE-2014-3477 dbus: denial of service flaw in dbus-daemon
bugzilla·2014-06-04·CVSS 4.0
CVE-2014-3477 [MEDIUM] CVE-2014-3477 dbus: denial of service flaw in dbus-daemon
CVE-2014-3477 dbus: denial of service flaw in dbus-daemon
Alban Crequy of Collabora Ltd. discovered a denial of service flaw in dbus-daemon. If a client (C1) was prohibited from sending a message to a service (S1), and S1 was not currently running, then C1 could attempt to send a message to S1's well-known bus name, causing dbus-daemon to start S1. When S1 had started and obtained its well-known bus name, the dbus-daemon evaluated its security policy, decided that it would not deliver the message to S1, and constructed an AccessDenied error. Instead of sending that AccessDenied error reply to C1 as a reply to the denied message, dbus-daemon incorrectly sent it to S1 as a reply to the request to obtain its well-known bus name. This would cause S1 to fail to initialize and exit, denying ser
http://advisories.mageia.org/MGASA-2014-0266.htmlhttp://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.8&id=24c590703ca47eb71ddef453de43126b90954567http://lists.opensuse.org/opensuse-updates/2014-06/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2014-07/msg00012.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00049.htmlhttp://seclists.org/oss-sec/2014/q2/509http://secunia.com/advisories/59428http://secunia.com/advisories/59611http://secunia.com/advisories/59798http://www.debian.org/security/2014/dsa-2971http://www.mandriva.com/security/advisories?name=MDVSA-2015:176http://www.securityfocus.com/bid/67986https://bugs.freedesktop.org/show_bug.cgi?id=78979http://advisories.mageia.org/MGASA-2014-0266.htmlhttp://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.8&id=24c590703ca47eb71ddef453de43126b90954567http://lists.opensuse.org/opensuse-updates/2014-06/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2014-07/msg00012.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00049.htmlhttp://seclists.org/oss-sec/2014/q2/509http://secunia.com/advisories/59428http://secunia.com/advisories/59611http://secunia.com/advisories/59798http://www.debian.org/security/2014/dsa-2971http://www.mandriva.com/security/advisories?name=MDVSA-2015:176http://www.securityfocus.com/bid/67986https://bugs.freedesktop.org/show_bug.cgi?id=78979
2014-07-01
Published