CVE Vulnerabilities

CVE-2014-3477

Published: Jul 01, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
3.6 MODERATE
AV:L/AC:L/Au:N/C:N/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D-Bus message to an inactive service.

Affected Software

NameVendorStart VersionEnd Version
D-busD-bus_project1.2.4.2 (including)1.2.4.2 (including)
D-busD-bus_project1.2.4.4 (including)1.2.4.4 (including)
D-busD-bus_project1.2.4.6 (including)1.2.4.6 (including)
DbusFreedesktop1.2.1 (including)1.2.1 (including)
DbusFreedesktop1.2.3 (including)1.2.3 (including)
DbusFreedesktop1.2.4 (including)1.2.4 (including)
DbusFreedesktop1.2.6 (including)1.2.6 (including)
DbusFreedesktop1.2.8 (including)1.2.8 (including)
DbusFreedesktop1.2.10 (including)1.2.10 (including)
DbusFreedesktop1.2.12 (including)1.2.12 (including)
DbusFreedesktop1.2.14 (including)1.2.14 (including)
DbusFreedesktop1.2.16 (including)1.2.16 (including)
DbusFreedesktop1.2.18 (including)1.2.18 (including)
DbusFreedesktop1.2.20 (including)1.2.20 (including)
DbusFreedesktop1.2.22 (including)1.2.22 (including)
DbusFreedesktop1.2.24 (including)1.2.24 (including)
DbusFreedesktop1.2.26 (including)1.2.26 (including)
DbusFreedesktop1.2.28 (including)1.2.28 (including)
DbusFreedesktop1.2.30 (including)1.2.30 (including)
DbusFreedesktop1.3.0 (including)1.3.0 (including)
DbusFreedesktop1.3.1 (including)1.3.1 (including)
DbusFreedesktop1.4.0 (including)1.4.0 (including)
DbusFreedesktop1.4.1 (including)1.4.1 (including)
DbusFreedesktop1.4.4 (including)1.4.4 (including)
DbusFreedesktop1.4.6 (including)1.4.6 (including)
DbusFreedesktop1.4.8 (including)1.4.8 (including)
DbusFreedesktop1.4.10 (including)1.4.10 (including)
DbusFreedesktop1.4.12 (including)1.4.12 (including)
DbusFreedesktop1.4.14 (including)1.4.14 (including)
DbusFreedesktop1.4.16 (including)1.4.16 (including)
DbusFreedesktop1.4.18 (including)1.4.18 (including)
DbusFreedesktop1.4.20 (including)1.4.20 (including)
DbusFreedesktop1.4.22 (including)1.4.22 (including)
DbusFreedesktop1.4.24 (including)1.4.24 (including)
DbusFreedesktop1.4.26 (including)1.4.26 (including)
DbusFreedesktop1.6.0 (including)1.6.0 (including)
DbusFreedesktop1.6.2 (including)1.6.2 (including)
DbusFreedesktop1.6.4 (including)1.6.4 (including)
DbusFreedesktop1.6.6 (including)1.6.6 (including)
DbusFreedesktop1.6.8 (including)1.6.8 (including)
DbusFreedesktop1.6.10 (including)1.6.10 (including)
DbusFreedesktop1.6.12 (including)1.6.12 (including)
DbusFreedesktop1.6.14 (including)1.6.14 (including)
DbusFreedesktop1.6.16 (including)1.6.16 (including)
DbusFreedesktop1.6.18 (including)1.6.18 (including)
DbusFreedesktop1.8.0 (including)1.8.0 (including)
DbusFreedesktop1.8.2 (including)1.8.2 (including)
DbusUbuntudevel*
DbusUbuntuesm-infra-legacy/trusty*
DbusUbuntulucid*
DbusUbuntuprecise*
DbusUbuntusaucy*
DbusUbuntutrusty*
DbusUbuntutrusty/esm*
DbusUbuntuupstream*

References