D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service (disconnect) via multiple messages that combine to have more than the allowed number of file descriptors for a single sendmsg call.
Name | Vendor | Start Version | End Version |
---|---|---|---|
D-bus | D-bus_project | * | 1.6.22 (including) |
Dbus | Freedesktop | 1.8.0 (including) | 1.8.0 (including) |
Dbus | Freedesktop | 1.8.2 (including) | 1.8.2 (including) |
Dbus | Freedesktop | 1.8.4 (including) | 1.8.4 (including) |
Dbus | Freedesktop | 1.8.6 (including) | 1.8.6 (including) |
Dbus | Ubuntu | precise | * |
Dbus | Ubuntu | trusty | * |
Dbus | Ubuntu | upstream | * |