CVE-2023-34969
published 2023-06-08CVE-2023-34969: D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.42%
69.9th percentile
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dbus | < dbus 1.14.8-1~deb12u1 (bookworm) | dbus 1.14.8-1~deb12u1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| freedesktop | dbus | >= 0 < 1.12.28-0+deb11u1 | 1.12.28-0+deb11u1 |
| freedesktop | dbus | >= 0 < 1.14.8-1~deb12u1 | 1.14.8-1~deb12u1 |
| freedesktop | dbus | >= 0 < 1.14.8-1 | 1.14.8-1 |
| freedesktop | dbus | >= 0 < 1.14.8-1 | 1.14.8-1 |
| freedesktop | dbus | >= 1.12.0 < 1.12.28 | 1.12.28 |
| freedesktop | dbus | >= 1.14.0 < 1.14.8 | 1.14.8 |
| freedesktop | dbus | >= 1.15.0 < 1.15.6 | 1.15.6 |
| msrc | cbl2_dbus_1.15.6-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
DBus vulnerability
vendor_ubuntu·2023-09-14
CVE-2023-34969 DBus vulnerability
Title: DBus vulnerability
Summary: DBus could be made to crash if it received a specially crafted request.
It was discovered that DBus incorrectly handled certain
invalid messages. A local attacker could possibly use
this issue to cause DBus to crash, resulting in a denial
of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Microsoft
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor m
vendor_msrc·2023-06-13·CVSS 6.5
CVE-2023-34969 [MEDIUM] D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor m
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus this is a denial-of-service vulnerability. The fixed versions are 1.12.28 1.14.8 and 1.15.6.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most rec
Red Hat
dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered
vendor_redhat·2023-06-06·CVSS 6.5
CVE-2023-34969 [MEDIUM] CWE-617 dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered
dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.
An assertion failure vulnerability was found in D-Bus. This issue occurs when a privileged monitoring connection (dbus-monitor, busctl monitor, gdbus monitor, or similar)
Debian
CVE-2023-34969: dbus - D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If...
vendor_debian·2023·CVSS 6.5
CVE-2023-34969 [MEDIUM] CVE-2023-34969: dbus - D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If...
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.
Scope: local
bookworm: resolved (fixed in 1.14.8-1~deb12u1)
bullseye: resolved (fixed in 1.12.28-0+deb11u1)
forky: resolved (fixed in 1.14.8-1)
sid: resolved (fixed in 1.14.8-1)
trixie: resolved (fixed in 1.14.8-1)
OSV
CVE-2023-34969: D-Bus before 1
osv·2023-06-08·CVSS 6.5
CVE-2023-34969 [MEDIUM] CVE-2023-34969: D-Bus before 1
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.
GHSA
GHSA-q652-p9gf-vfq3: D-Bus before 1
ghsa_unreviewed·2023-06-08
CVE-2023-34969 [MEDIUM] CWE-400 GHSA-q652-p9gf-vfq3: D-Bus before 1
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.
No detection rules found.
No public exploits indexed.
Trailofbits
Celebrating our 2023 open-source contributions
blogs_trailofbits·2024-01-24
Celebrating our 2023 open-source contributions
At Trail of Bits, we pride ourselves on making our best tools open source, such as Slither, PolyTracker, and RPC Investigator. But while this post is about open source, it’s not about our tools…
In 2023, our employees submitted over 450 pull requests (PRs) that were merged into non-Trail of Bits repositories. This demonstrates our commitment to securing the software ecosystem as a whole and to improving software quality for everyone. A representative list of contributions appears at the end of this post, but here are some highlights:
- Sigstore-conformance, a vital component of our Sigstore initiative in open-source engineering, functions as an integration test suite for diverse Sigstore client implementations. Ensuring conformity to the Sigstore client testing suite, it rigorously evalu
Trailofbits
Celebrating our 2023 open-source contributions
blogs_trailofbits·2024-01-24
Celebrating our 2023 open-source contributions
At Trail of Bits, we pride ourselves on making our best tools open source, such as Slither , PolyTracker , and RPC Investigator . But while this post is about open source, it’s not about our tools…
In 2023, our employees submitted over 450 pull requests (PRs) that were merged into non-Trail of Bits repositories. This demonstrates our commitment to securing the software ecosystem as a whole and to improving software quality for everyone. A representative list of contributions appears at the end of this post, but here are some highlights:
Sigstore-conformance , a vital component of our Sigstore initiative in open-source engineering, functions as an integration test suite for diverse Sigstore client implementations. Ensuring conformity to the Sigstore client testing suite, it rigorously eva
Bugzilla
CVE-2023-34969 dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered
bugzilla·2023-06-07·CVSS 6.5
CVE-2023-34969 [MEDIUM] CVE-2023-34969 dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered
CVE-2023-34969 dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered
An assertion failure in dbus-daemon when a privileged Monitoring connection (dbus-monitor, busctl monitor, gdbus monitor or similar) is active, and a message from the bus driver cannot be delivered to a client connection due to rules or outgoing message quota. This is a denial of service if triggered maliciously by a local attacker
In other words, if a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances.
Vulnerable versions:
1.15.x before 1.15.6
1
https://gitlab.freedesktop.org/dbus/dbus/-/issues/457https://lists.debian.org/debian-lts-announce/2023/10/msg00033.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/https://security.netapp.com/advisory/ntap-20231208-0007/https://gitlab.freedesktop.org/dbus/dbus/-/issues/457https://lists.debian.org/debian-lts-announce/2023/10/msg00033.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/https://security.netapp.com/advisory/ntap-20231208-0007/
2023-06-08
Published