CVE Vulnerabilities

CVE-2014-3638

Published: Sep 22, 2014 | Modified: Dec 27, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a large number of method calls.

Affected Software

Name Vendor Start Version End Version
D-bus D-bus_project * 1.6.22 (including)
Dbus Freedesktop 1.6.0 (including) 1.6.0 (including)
Dbus Freedesktop 1.6.2 (including) 1.6.2 (including)
Dbus Freedesktop 1.6.4 (including) 1.6.4 (including)
Dbus Freedesktop 1.6.6 (including) 1.6.6 (including)
Dbus Freedesktop 1.6.8 (including) 1.6.8 (including)
Dbus Freedesktop 1.6.10 (including) 1.6.10 (including)
Dbus Freedesktop 1.6.12 (including) 1.6.12 (including)
Dbus Freedesktop 1.6.14 (including) 1.6.14 (including)
Dbus Freedesktop 1.6.16 (including) 1.6.16 (including)
Dbus Freedesktop 1.6.18 (including) 1.6.18 (including)
Dbus Freedesktop 1.6.20 (including) 1.6.20 (including)
Dbus Freedesktop 1.8.0 (including) 1.8.0 (including)
Dbus Freedesktop 1.8.2 (including) 1.8.2 (including)
Dbus Freedesktop 1.8.4 (including) 1.8.4 (including)
Dbus Freedesktop 1.8.6 (including) 1.8.6 (including)
Dbus Ubuntu lucid *
Dbus Ubuntu precise *
Dbus Ubuntu trusty *
Dbus Ubuntu upstream *

References