CVE-2014-3636
published 2014-10-25CVE-2014-3636: D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and…
PriorityP47low1.9CVSS 2.0
AVLACMAuNCNINAP
EPSS
0.51%
40.4th percentile
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service (disconnect) via multiple messages that combine to have more than the allowed number of file descriptors for a single sendmsg call.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| d-bus_project | d-bus | <= 1.6.22 | — |
| debian | dbus | < dbus 1.8.10-1 (bookworm) | dbus 1.8.10-1 (bookworm) |
| debian | dbus | < dbus 1.8.8-1 (bookworm) | dbus 1.8.8-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv4.4MEDIUM
vendor_ubuntu4.4MEDIUM
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dbus: local denial of service via incomplete fix for CVE-2014-3636
vendor_redhat·2014-11-10·CVSS 1.9
CVE-2014-7824 [LOW] dbus: local denial of service via incomplete fix for CVE-2014-3636
dbus: local denial of service via incomplete fix for CVE-2014-3636
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
Package: dbus (Red Hat Enterprise Linux 5) - Not affected
Package: dbus (Red Hat Enterprise Linux 6) - Not affected
Package: dbus (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
DBus vulnerabilities
vendor_ubuntu·2014-09-22·CVSS 4.4
CVE-2014-3635 [MEDIUM] DBus vulnerabilities
Title: DBus vulnerabilities
Summary: Several security issues were fixed in DBus.
Simon McVittie discovered that DBus incorrectly handled the file
descriptors message limit. A local attacker could use this issue to cause
DBus to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3635)
Alban Crequy discovered that DBus incorrectly handled a large number of
file descriptor messages. A local attacker could use this issue to cause
DBus to stop responding, resulting in a denial of service. This issue only
applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-3636)
Alban Crequy discovered that DBus incorrectly handled certain file
descriptor messages. A local attacker could use this iss
Red Hat
dbus: denial of service by queuing or splitting file descriptors
vendor_redhat·2014-09-16·CVSS 1.9
CVE-2014-3636 [LOW] dbus: denial of service by queuing or splitting file descriptors
dbus: denial of service by queuing or splitting file descriptors
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service (disconnect) via multiple messages that combine to have more than the allowed number of file descriptors for a single sendmsg call.
Package: dbus (Red Hat Enterprise Linux 5) - Will not fix
Package: dbus (Red Hat Enterprise Linux 6) - Under investigation
Package: dbus (Red Hat Enterprise Linux 7) - Under investigation
Debian
CVE-2014-7824: dbus - D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1...
vendor_debian·2014·CVSS 1.9
CVE-2014-7824 [LOW] CVE-2014-7824: dbus - D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1...
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
Scope: local
bookworm: resolved (fixed in 1.8.10-1)
bullseye: resolved (fixed in 1.8.10-1)
forky: resolved (fixed in 1.8.10-1)
sid: resolved (fixed in 1.8.10-1)
trixie: resolved (fixed in 1.8.10-1)
Debian
CVE-2014-3636: dbus - D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local user...
vendor_debian·2014·CVSS 1.9
CVE-2014-3636 [LOW] CVE-2014-3636: dbus - D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local user...
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service (disconnect) via multiple messages that combine to have more than the allowed number of file descriptors for a single sendmsg call.
Scope: local
bookworm: resolved (fixed in 1.8.8-1)
bullseye: resolved (fixed in 1.8.8-1)
forky: resolved (fixed in 1.8.8-1)
sid: resolved (fixed in 1.8.8-1)
trixie: resolved (fixed in 1.8.8-1)
GHSA
GHSA-2vxr-xm37-7x29: D-Bus 1
ghsa_unreviewed·2022-05-17·CVSS 1.9
CVE-2014-7824 [LOW] GHSA-2vxr-xm37-7x29: D-Bus 1
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
GHSA
GHSA-vh38-h8j6-grqm: D-Bus 1
ghsa_unreviewed·2022-05-14
CVE-2014-3636 [LOW] GHSA-vh38-h8j6-grqm: D-Bus 1
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service (disconnect) via multiple messages that combine to have more than the allowed number of file descriptors for a single sendmsg call.
OSV
CVE-2014-7824: D-Bus 1
osv·2014-11-18·CVSS 1.9
CVE-2014-7824 [LOW] CVE-2014-7824: D-Bus 1
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
OSV
CVE-2014-3636: D-Bus 1
osv·2014-10-25·CVSS 1.9
CVE-2014-3636 [LOW] CVE-2014-3636: D-Bus 1
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service (disconnect) via multiple messages that combine to have more than the allowed number of file descriptors for a single sendmsg call.
OSV
dbus vulnerabilities
osv·2014-09-22·CVSS 4.4
CVE-2014-3635 [MEDIUM] dbus vulnerabilities
dbus vulnerabilities
Simon McVittie discovered that DBus incorrectly handled the file
descriptors message limit. A local attacker could use this issue to cause
DBus to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3635)
Alban Crequy discovered that DBus incorrectly handled a large number of
file descriptor messages. A local attacker could use this issue to cause
DBus to stop responding, resulting in a denial of service. This issue only
applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-3636)
Alban Crequy discovered that DBus incorrectly handled certain file
descriptor messages. A local attacker could use this issue to cause DBus
to maintain persistent connections, possibly
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7824 dbus: local denial of service via incomplete fix for CVE-2014-3636 [fedora-all]
bugzilla·2014-12-12·CVSS 1.9
CVE-2014-7824 [LOW] CVE-2014-7824 dbus: local denial of service via incomplete fix for CVE-2014-3636 [fedora-all]
CVE-2014-7824 dbus: local denial of service via incomplete fix for CVE-2014-3636 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2014-7824 mingw-dbus: dbus: local denial of service via incomplete fix for CVE-2014-3636 [fedora-all]
bugzilla·2014-12-12·CVSS 1.9
CVE-2014-7824 [LOW] CVE-2014-7824 mingw-dbus: dbus: local denial of service via incomplete fix for CVE-2014-3636 [fedora-all]
CVE-2014-7824 mingw-dbus: dbus: local denial of service via incomplete fix for CVE-2014-3636 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2014-7824 dbus: local denial of service via incomplete fix for CVE-2014-3636
bugzilla·2014-12-12·CVSS 1.9
CVE-2014-7824 [LOW] CVE-2014-7824 dbus: local denial of service via incomplete fix for CVE-2014-3636
CVE-2014-7824 dbus: local denial of service via incomplete fix for CVE-2014-3636
The patch issued by the D-Bus maintainers for CVE-2014-3636 was based on
incorrect reasoning, and does not fully prevent the attack described as
"CVE-2014-3636 part A", which is repeated below. Preventing that attack
requires raising the system dbus-daemon's RLIMIT_NOFILE (ulimit -n) to a
higher value.
To avoid propagating that higher limit to activatable system services,
it is desirable to start the system dbus-daemon as root so it can store
its previous limit, raise its limit, drop root privileges (which its
default configuration will do automatically), and restore the previous
limit before launching activatable services. Some operating system
distributions, such as anything using the upstream-supplied sys
Bugzilla
CVE-2014-7824 mingw-dbus: dbus: local denial of service via incomplete fix for CVE-2014-3636 [epel-7]
bugzilla·2014-12-12·CVSS 1.9
CVE-2014-7824 [LOW] CVE-2014-7824 mingw-dbus: dbus: local denial of service via incomplete fix for CVE-2014-3636 [epel-7]
CVE-2014-7824 mingw-dbus: dbus: local denial of service via incomplete fix for CVE-2014-3636 [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for min
Bugzilla
CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 mingw-dbus: various flaws [fedora-all]
bugzilla·2014-09-17·CVSS 4.4
CVE-2014-3638 [MEDIUM] CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 mingw-dbus: various flaws [fedora-all]
CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 mingw-dbus: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 mingw-dbus: various flaws [epel-7]
bugzilla·2014-09-17·CVSS 4.4
CVE-2014-3638 [MEDIUM] CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 mingw-dbus: various flaws [epel-7]
CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 mingw-dbus: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for
Bugzilla
CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 dbus: various flaws [fedora-all]
bugzilla·2014-09-17·CVSS 4.4
CVE-2014-3638 [MEDIUM] CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 dbus: various flaws [fedora-all]
CVE-2014-3638 CVE-2014-3639 CVE-2014-3636 CVE-2014-3637 CVE-2014-3635 dbus: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2014-3636 dbus: denial of service by queuing or splitting file descriptors
bugzilla·2014-09-11·CVSS 1.9
CVE-2014-3636 [LOW] CVE-2014-3636 dbus: denial of service by queuing or splitting file descriptors
CVE-2014-3636 dbus: denial of service by queuing or splitting file descriptors
A denial of service flaw was reported in D-Bus's file descriptor passing. A local, malicious user could use this flaw to cause a denial of service (prevent new connections to the bus, or disconnect something from the bus) by queuing up a large number of file descriptors to send, or by splitting a message to allow more file descriptors than expected to be sent.
It is believed that versions 1.3.0 and later are affected.
Acknowledgements:
Red Hat would like to thank D-Bus upstream for reporting this issue. Upstream acknowledges Alban Crequy as the original reporter.
Discussion:
Created attachment 936437
initial patch from upstream
---
Created dbus tracking bugs for this issue:
Affects: fedora-all [bug 1142
http://advisories.mageia.org/MGASA-2014-0395.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00049.htmlhttp://secunia.com/advisories/61378http://www.debian.org/security/2014/dsa-3026http://www.mandriva.com/security/advisories?name=MDVSA-2015:176http://www.openwall.com/lists/oss-security/2014/09/16/9http://www.securitytracker.com/id/1030864http://www.ubuntu.com/usn/USN-2352-1https://bugs.freedesktop.org/show_bug.cgi?id=82820http://advisories.mageia.org/MGASA-2014-0395.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00049.htmlhttp://secunia.com/advisories/61378http://www.debian.org/security/2014/dsa-3026http://www.mandriva.com/security/advisories?name=MDVSA-2015:176http://www.openwall.com/lists/oss-security/2014/09/16/9http://www.securitytracker.com/id/1030864http://www.ubuntu.com/usn/USN-2352-1https://bugs.freedesktop.org/show_bug.cgi?id=82820
2014-10-25
Published