CVE Vulnerabilities

CVE-2014-3477

Published: Jul 01, 2014 | Modified: Dec 27, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
3.6 MODERATE
AV:L/AC:L/Au:N/C:N/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D-Bus message to an inactive service.

Affected Software

Name Vendor Start Version End Version
D-bus D-bus_project 1.2.4.2 (including) 1.2.4.2 (including)
D-bus D-bus_project 1.2.4.4 (including) 1.2.4.4 (including)
D-bus D-bus_project 1.2.4.6 (including) 1.2.4.6 (including)
Dbus Freedesktop 1.2.1 (including) 1.2.1 (including)
Dbus Freedesktop 1.2.3 (including) 1.2.3 (including)
Dbus Freedesktop 1.2.4 (including) 1.2.4 (including)
Dbus Freedesktop 1.2.6 (including) 1.2.6 (including)
Dbus Freedesktop 1.2.8 (including) 1.2.8 (including)
Dbus Freedesktop 1.2.10 (including) 1.2.10 (including)
Dbus Freedesktop 1.2.12 (including) 1.2.12 (including)
Dbus Freedesktop 1.2.14 (including) 1.2.14 (including)
Dbus Freedesktop 1.2.16 (including) 1.2.16 (including)
Dbus Freedesktop 1.2.18 (including) 1.2.18 (including)
Dbus Freedesktop 1.2.20 (including) 1.2.20 (including)
Dbus Freedesktop 1.2.22 (including) 1.2.22 (including)
Dbus Freedesktop 1.2.24 (including) 1.2.24 (including)
Dbus Freedesktop 1.2.26 (including) 1.2.26 (including)
Dbus Freedesktop 1.2.28 (including) 1.2.28 (including)
Dbus Freedesktop 1.2.30 (including) 1.2.30 (including)
Dbus Freedesktop 1.3.0 (including) 1.3.0 (including)
Dbus Freedesktop 1.3.1 (including) 1.3.1 (including)
Dbus Freedesktop 1.4.0 (including) 1.4.0 (including)
Dbus Freedesktop 1.4.1 (including) 1.4.1 (including)
Dbus Freedesktop 1.4.4 (including) 1.4.4 (including)
Dbus Freedesktop 1.4.6 (including) 1.4.6 (including)
Dbus Freedesktop 1.4.8 (including) 1.4.8 (including)
Dbus Freedesktop 1.4.10 (including) 1.4.10 (including)
Dbus Freedesktop 1.4.12 (including) 1.4.12 (including)
Dbus Freedesktop 1.4.14 (including) 1.4.14 (including)
Dbus Freedesktop 1.4.16 (including) 1.4.16 (including)
Dbus Freedesktop 1.4.18 (including) 1.4.18 (including)
Dbus Freedesktop 1.4.20 (including) 1.4.20 (including)
Dbus Freedesktop 1.4.22 (including) 1.4.22 (including)
Dbus Freedesktop 1.4.24 (including) 1.4.24 (including)
Dbus Freedesktop 1.4.26 (including) 1.4.26 (including)
Dbus Freedesktop 1.6.0 (including) 1.6.0 (including)
Dbus Freedesktop 1.6.2 (including) 1.6.2 (including)
Dbus Freedesktop 1.6.4 (including) 1.6.4 (including)
Dbus Freedesktop 1.6.6 (including) 1.6.6 (including)
Dbus Freedesktop 1.6.8 (including) 1.6.8 (including)
Dbus Freedesktop 1.6.10 (including) 1.6.10 (including)
Dbus Freedesktop 1.6.12 (including) 1.6.12 (including)
Dbus Freedesktop 1.6.14 (including) 1.6.14 (including)
Dbus Freedesktop 1.6.16 (including) 1.6.16 (including)
Dbus Freedesktop 1.6.18 (including) 1.6.18 (including)
Dbus Freedesktop 1.8.0 (including) 1.8.0 (including)
Dbus Freedesktop 1.8.2 (including) 1.8.2 (including)
Dbus Ubuntu devel *
Dbus Ubuntu lucid *
Dbus Ubuntu precise *
Dbus Ubuntu saucy *
Dbus Ubuntu trusty *
Dbus Ubuntu upstream *

References