cbcvebase.
CVE-2014-3532
published 2014-07-19

CVE-2014-3532: dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus…

PriorityP48low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.45%
36.1th percentile
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandbus< dbus 1.8.6-1 (bookworm)dbus 1.8.6-1 (bookworm)
debiandebian_linux
freedesktopdbus>= 0 < 1.8.6-11.8.6-1
freedesktopdbus>= 0 < 1.8.6-11.8.6-1
freedesktopdbus>= 0 < 1.8.6-11.8.6-1
freedesktopdbus>= 0 < 1.8.6-11.8.6-1
freedesktopdbus>= 0 < 1.6.18-0ubuntu4.11.6.18-0ubuntu4.1
freedesktopdbus>= 1.3.0 < 1.6.221.6.22
freedesktopdbus>= 1.8.0 < 1.8.61.8.6
mageiamageia
mageiamageia
opensuseopensuse
oraclesolaris

CVSS provenance

nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv4.0MEDIUM
vendor_ubuntu4.0MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.