CVE Vulnerabilities

CVE-2014-3638

Published: Sep 22, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a large number of method calls.

Affected Software

NameVendorStart VersionEnd Version
D-busD-bus_project*1.6.22 (including)
DbusFreedesktop1.6.0 (including)1.6.0 (including)
DbusFreedesktop1.6.2 (including)1.6.2 (including)
DbusFreedesktop1.6.4 (including)1.6.4 (including)
DbusFreedesktop1.6.6 (including)1.6.6 (including)
DbusFreedesktop1.6.8 (including)1.6.8 (including)
DbusFreedesktop1.6.10 (including)1.6.10 (including)
DbusFreedesktop1.6.12 (including)1.6.12 (including)
DbusFreedesktop1.6.14 (including)1.6.14 (including)
DbusFreedesktop1.6.16 (including)1.6.16 (including)
DbusFreedesktop1.6.18 (including)1.6.18 (including)
DbusFreedesktop1.6.20 (including)1.6.20 (including)
DbusFreedesktop1.8.0 (including)1.8.0 (including)
DbusFreedesktop1.8.2 (including)1.8.2 (including)
DbusFreedesktop1.8.4 (including)1.8.4 (including)
DbusFreedesktop1.8.6 (including)1.8.6 (including)
DbusUbuntuesm-infra-legacy/trusty*
DbusUbuntulucid*
DbusUbuntuprecise*
DbusUbuntutrusty*
DbusUbuntutrusty/esm*
DbusUbuntuupstream*

References