LOW
dbus: denial of service by creating unkillable D-Bus connections
Published Sep 22, 2014
2.1
LOWCVSS 2.0
EPSS 0.45%
Description
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections for processes that have terminated, which allows local users to cause a denial of service via a D-bus message containing a D-Bus connection file descriptor.
Affected products
No data.
Configuration 1
OR
- 1.3.0
- 1.3.1
- 1.4.0
- 1.4.1
- 1.4.4
- 1.4.6
- 1.4.8
- 1.4.10
- 1.4.12
- 1.4.14
- 1.4.16
- 1.4.18
- 1.4.20
- 1.4.22
- 1.4.24
- 1.4.26
- 1.5.0
- 1.5.2
- 1.5.4
- 1.5.6
- 1.5.8
- 1.5.10
- 1.5.12
- 1.6.0
- 1.6.2
- 1.6.4
- 1.6.6
- 1.6.8
- 1.6.10
- 1.6.12
- 1.6.14
- 1.6.16
- 1.6.18
- 1.6.20
- 1.6.22
- 1.8.0
- 1.8.2
- 1.8.4
- 1.8.6
No data.
Red Hat Enterprise Linux 5
dbus
Will not fix
Red Hat Enterprise Linux 6
dbus
Under investigation
Red Hat Enterprise Linux 7
dbus
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | dbus | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | dbus | Under investigation | n/a |
| Red Hat Enterprise Linux 7 | dbus | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (16)
- http://advisories.mageia.org/MGASA-2014-0395.html x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-updates/2014-09/msg00049.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/61378 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2014/dsa-3026 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:176 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2014/09/16/9 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2019/06/24/13 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2019/06/24/14 mailing-listx_refsource_MLIST
- http://www.securitytracker.com/id/1030864 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-2352-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2014-3637 Vendor Advisory
- https://bugs.freedesktop.org/show_bug.cgi?id=80559 x_refsource_CONFIRMPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=1140527 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-3595 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-3637
- https://www.cve.org/CVERecord?id=CVE-2014-3637
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 22, 2014
Updated Aug 6, 2024
Reserved May 14, 2014
Link CVE-2014-3637
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2014-3595 Assigner redhat
Published Sep 22, 2014
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2014-3595