CVE-2014-3532
published 2014-07-19CVE-2014-3532: dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.45%
36.1th percentile
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dbus | < dbus 1.8.6-1 (bookworm) | dbus 1.8.6-1 (bookworm) |
| debian | debian_linux | — | — |
| freedesktop | dbus | >= 0 < 1.8.6-1 | 1.8.6-1 |
| freedesktop | dbus | >= 0 < 1.8.6-1 | 1.8.6-1 |
| freedesktop | dbus | >= 0 < 1.8.6-1 | 1.8.6-1 |
| freedesktop | dbus | >= 0 < 1.8.6-1 | 1.8.6-1 |
| freedesktop | dbus | >= 0 < 1.6.18-0ubuntu4.1 | 1.6.18-0ubuntu4.1 |
| freedesktop | dbus | >= 1.3.0 < 1.6.22 | 1.6.22 |
| freedesktop | dbus | >= 1.8.0 < 1.8.6 | 1.8.6 |
| mageia | mageia | — | — |
| mageia | mageia | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv4.0MEDIUM
vendor_ubuntu4.0MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7x26-2rv5-r99f: dbus 1
ghsa_unreviewed·2022-05-13
CVE-2014-3532 [LOW] CWE-20 GHSA-7x26-2rv5-r99f: dbus 1
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.
OSV
CVE-2014-3532: dbus 1
osv·2014-07-19·CVSS 2.1
CVE-2014-3532 [LOW] CVE-2014-3532: dbus 1
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.
OSV
dbus vulnerabilities
osv·2014-07-08·CVSS 4.0
CVE-2014-3477 [MEDIUM] dbus vulnerabilities
dbus vulnerabilities
Alban Crequy discovered that dbus-daemon incorrectly sent AccessDenied
errors to the service instead of the client when enforcing permissions. A
local user can use this issue to possibly deny access to the service.
(CVE-2014-3477)
Alban Crequy discovered that dbus-daemon incorrectly handled certain file
descriptors. A local attacker could use this issue to cause services or
clients to disconnect, resulting in a denial of service. (CVE-2014-3532,
CVE-2014-3533)
Ubuntu
DBus vulnerabilities
vendor_ubuntu·2014-07-08·CVSS 4.0
CVE-2014-3477 [MEDIUM] DBus vulnerabilities
Title: DBus vulnerabilities
Summary: Several security issues were fixed in DBus.
Alban Crequy discovered that dbus-daemon incorrectly sent AccessDenied
errors to the service instead of the client when enforcing permissions. A
local user can use this issue to possibly deny access to the service.
(CVE-2014-3477)
Alban Crequy discovered that dbus-daemon incorrectly handled certain file
descriptors. A local attacker could use this issue to cause services or
clients to disconnect, resulting in a denial of service. (CVE-2014-3532,
CVE-2014-3533)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
dbus: denial of service in file descriptor passing feature
vendor_redhat·2014-07-02·CVSS 2.1
CVE-2014-3532 [LOW] dbus: denial of service in file descriptor passing feature
dbus: denial of service in file descriptor passing feature
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.
Package: dbus (Red Hat Enterprise Linux 5) - Will not fix
Package: dbus (Red Hat Enterprise Linux 6) - Will not fix
Package: dbus (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-3532: dbus - dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc...
vendor_debian·2014·CVSS 2.1
CVE-2014-3532 [LOW] CVE-2014-3532: dbus - dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc...
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3533 CVE-2014-3532 mingw-dbus: various flaws [fedora-all]
bugzilla·2014-07-02·CVSS 2.1
CVE-2014-3533 [LOW] CVE-2014-3533 CVE-2014-3532 mingw-dbus: various flaws [fedora-all]
CVE-2014-3533 CVE-2014-3532 mingw-dbus: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2014-3533 CVE-2014-3532 dbus: various flaws [fedora-all]
bugzilla·2014-07-02·CVSS 2.1
CVE-2014-3533 [LOW] CVE-2014-3533 CVE-2014-3532 dbus: various flaws [fedora-all]
CVE-2014-3533 CVE-2014-3532 dbus: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2014-3533 CVE-2014-3532 mingw-dbus: various flaws [epel-7]
bugzilla·2014-07-02·CVSS 2.1
CVE-2014-3533 [LOW] CVE-2014-3533 CVE-2014-3532 mingw-dbus: various flaws [epel-7]
CVE-2014-3533 CVE-2014-3532 mingw-dbus: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-7 tracking bug for mingw-dbus: see bloc
Bugzilla
CVE-2014-3532 dbus: denial of service in file descriptor passing feature
bugzilla·2014-06-30·CVSS 2.1
CVE-2014-3532 [LOW] CVE-2014-3532 dbus: denial of service in file descriptor passing feature
CVE-2014-3532 dbus: denial of service in file descriptor passing feature
A flaw was reported in D-Bus's file descriptor passing feature. A local attacker could use this flaw to cause a service or application to disconnect from the bus, typically resulting in that service or application exiting.
It is reported that versions 1.3.0 and newer are affected.
Acknowledgements:
Red Hat would like to thank D-Bus upstream for reporting this issue. Upstream acknowledges Alban Crequy of Collabora Ltd. as the original reporter.
Discussion:
This is now public:
http://openwall.com/lists/oss-security/2014/07/02/4
---
Created dbus tracking bugs for this issue:
Affects: fedora-all [bug 1115636]
---
Created mingw-dbus tracking bugs for this issue:
Affects: fedora-all [bug 1115637]
Affects: epel-
http://advisories.mageia.org/MGASA-2014-0294.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00049.htmlhttp://openwall.com/lists/oss-security/2014/07/02/4http://secunia.com/advisories/59611http://secunia.com/advisories/59798http://secunia.com/advisories/60236http://www.debian.org/security/2014/dsa-2971http://www.mandriva.com/security/advisories?name=MDVSA-2015:176http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttps://bugs.freedesktop.org/show_bug.cgi?id=80163http://advisories.mageia.org/MGASA-2014-0294.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00049.htmlhttp://openwall.com/lists/oss-security/2014/07/02/4http://secunia.com/advisories/59611http://secunia.com/advisories/59798http://secunia.com/advisories/60236http://www.debian.org/security/2014/dsa-2971http://www.mandriva.com/security/advisories?name=MDVSA-2015:176http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttps://bugs.freedesktop.org/show_bug.cgi?id=80163
2014-07-19
Published