CVE-2014-3635
published 2014-09-22CVE-2014-3635: Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set…
PriorityP422medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.49%
38.7th percentile
Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows local users to cause a denial of service (dbus-daemon crash) or possibly execute arbitrary code by sending one more file descriptor than the limit, which triggers a heap-based buffer overflow or an assertion failure.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-bus_project | d-bus | <= 1.6.22 | — |
| debian | dbus | < dbus 1.8.8-1 (bookworm) | dbus 1.8.8-1 (bookworm) |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | >= 0 < 1.8.8-1 | 1.8.8-1 |
| freedesktop | dbus | >= 0 < 1.8.8-1 | 1.8.8-1 |
| freedesktop | dbus | >= 0 < 1.8.8-1 | 1.8.8-1 |
| freedesktop | dbus | >= 0 < 1.8.8-1 | 1.8.8-1 |
| freedesktop | dbus | >= 0 < 1.6.18-0ubuntu4.2 | 1.6.18-0ubuntu4.2 |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
DBus vulnerabilities
vendor_ubuntu·2014-09-22·CVSS 4.4
CVE-2014-3635 [MEDIUM] DBus vulnerabilities
Title: DBus vulnerabilities
Summary: Several security issues were fixed in DBus.
Simon McVittie discovered that DBus incorrectly handled the file
descriptors message limit. A local attacker could use this issue to cause
DBus to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3635)
Alban Crequy discovered that DBus incorrectly handled a large number of
file descriptor messages. A local attacker could use this issue to cause
DBus to stop responding, resulting in a denial of service. This issue only
applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-3636)
Alban Crequy discovered that DBus incorrectly handled certain file
descriptor messages. A local attacker could use this iss
Red Hat
dbus: heap-based buffer overflow flaw in file descriptor passing
vendor_redhat·2014-09-16·CVSS 4.4
CVE-2014-3635 [MEDIUM] CWE-122 dbus: heap-based buffer overflow flaw in file descriptor passing
dbus: heap-based buffer overflow flaw in file descriptor passing
Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows local users to cause a denial of service (dbus-daemon crash) or possibly execute arbitrary code by sending one more file descriptor than the limit, which triggers a heap-based buffer overflow or an assertion failure.
Package: dbus (Red Hat Enterprise Linux 5) - Will not fix
Package: dbus (Red Hat Enterprise Linux 6) - Not affected
Package: dbus (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-3635: dbus - Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8...
vendor_debian·2014·CVSS 4.4
CVE-2014-3635 [MEDIUM] CVE-2014-3635: dbus - Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8...
Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows local users to cause a denial of service (dbus-daemon crash) or possibly execute arbitrary code by sending one more file descriptor than the limit, which triggers a heap-based buffer overflow or an assertion failure.
Scope: local
bookworm: resolved (fixed in 1.8.8-1)
bullseye: resolved (fixed in 1.8.8-1)
forky: resolved (fixed in 1.8.8-1)
sid: resolved (fixed in 1.8.8-1)
trixie: resolved (fixed in 1.8.8-1)
GHSA
GHSA-hm35-xvpf-f225: Off-by-one error in D-Bus 1
ghsa_unreviewed·2022-05-14
CVE-2014-3635 [MEDIUM] CWE-119 GHSA-hm35-xvpf-f225: Off-by-one error in D-Bus 1
Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows local users to cause a denial of service (dbus-daemon crash) or possibly execute arbitrary code by sending one more file descriptor than the limit, which triggers a heap-based buffer overflow or an assertion failure.
OSV
dbus vulnerabilities
osv·2014-09-22·CVSS 4.4
CVE-2014-3635 [MEDIUM] dbus vulnerabilities
dbus vulnerabilities
Simon McVittie discovered that DBus incorrectly handled the file
descriptors message limit. A local attacker could use this issue to cause
DBus to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3635)
Alban Crequy discovered that DBus incorrectly handled a large number of
file descriptor messages. A local attacker could use this issue to cause
DBus to stop responding, resulting in a denial of service. This issue only
applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-3636)
Alban Crequy discovered that DBus incorrectly handled certain file
descriptor messages. A local attacker could use this issue to cause DBus
to maintain persistent connections, possibly
OSV
CVE-2014-3635: Off-by-one error in D-Bus 1
osv·2014-09-22·CVSS 4.4
CVE-2014-3635 [MEDIUM] CVE-2014-3635: Off-by-one error in D-Bus 1
Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows local users to cause a denial of service (dbus-daemon crash) or possibly execute arbitrary code by sending one more file descriptor than the limit, which triggers a heap-based buffer overflow or an assertion failure.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 mingw-dbus: various flaws [fedora-all]
bugzilla·2014-09-17·CVSS 4.4
CVE-2014-3638 [MEDIUM] CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 mingw-dbus: various flaws [fedora-all]
CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 mingw-dbus: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 mingw-dbus: various flaws [epel-7]
bugzilla·2014-09-17·CVSS 4.4
CVE-2014-3638 [MEDIUM] CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 mingw-dbus: various flaws [epel-7]
CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 mingw-dbus: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for
Bugzilla
CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 dbus: various flaws [fedora-all]
bugzilla·2014-09-17·CVSS 4.4
CVE-2014-3638 [MEDIUM] CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 dbus: various flaws [fedora-all]
CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 dbus: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2014-3635 dbus: heap-based buffer overflow flaw in file descriptor passing
bugzilla·2014-09-11·CVSS 4.4
CVE-2014-3635 [MEDIUM] CVE-2014-3635 dbus: heap-based buffer overflow flaw in file descriptor passing
CVE-2014-3635 dbus: heap-based buffer overflow flaw in file descriptor passing
A heap-based buffer overflow flaw was reported in D-Bus's file descriptor passing. On 64-bit systems, if the max_message_unix_fds limit was set to an odd number, a local, malicious user could send one more file descriptor than expected. This would cause the dbus-daemon to crash or, potentially, execute arbitrary code.
It is believed that versions 1.3.0 and later are affected.
Acknowledgements:
Red Hat would like to thank D-Bus upstream for reporting this issue. Upstream acknowledges Simon McVittie as the original reporter.
Discussion:
Created attachment 936433
initial patch from upstream
---
Created attachment 936434
silence a compiler warning in the previous patch
---
Created attachment 936435
regress
http://advisories.mageia.org/MGASA-2014-0395.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00049.htmlhttp://secunia.com/advisories/61378http://www.debian.org/security/2014/dsa-3026http://www.mandriva.com/security/advisories?name=MDVSA-2015:176http://www.openwall.com/lists/oss-security/2014/09/16/9http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1030864http://www.ubuntu.com/usn/USN-2352-1https://bugs.freedesktop.org/show_bug.cgi?id=83622http://advisories.mageia.org/MGASA-2014-0395.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00049.htmlhttp://secunia.com/advisories/61378http://www.debian.org/security/2014/dsa-3026http://www.mandriva.com/security/advisories?name=MDVSA-2015:176http://www.openwall.com/lists/oss-security/2014/09/16/9http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1030864http://www.ubuntu.com/usn/USN-2352-1https://bugs.freedesktop.org/show_bug.cgi?id=83622
2014-09-22
Published