cbcvebase.
CVE-2014-3532
published 2014-07-19

CVE-2014-3532: dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus…

low2.1CVSS 3.1
AVLACLAuNCNINAP
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandbus< dbus 1.8.6-1 (bookworm)dbus 1.8.6-1 (bookworm)
debiandebian_linux
freedesktopdbus>= 0 < 1.8.6-11.8.6-1
freedesktopdbus>= 0 < 1.8.6-11.8.6-1
freedesktopdbus>= 0 < 1.8.6-11.8.6-1
freedesktopdbus>= 0 < 1.8.6-11.8.6-1
freedesktopdbus>= 0 < 1.6.18-0ubuntu4.11.6.18-0ubuntu4.1
freedesktopdbus>= 1.3.0 < 1.6.221.6.22
freedesktopdbus>= 1.8.0 < 1.8.61.8.6
mageiamageia
mageiamageia
opensuseopensuse
oraclesolaris

CVSS provenance

nvd2.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv4.0MEDIUM