1.9

CVE-2013-2168

The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of service (service crash) via a crafted message.

Data is provided by the National Vulnerability Database (NVD)
FreedesktopDbus Version1.4.0
FreedesktopDbus Version1.4.1
FreedesktopDbus Version1.4.4
FreedesktopDbus Version1.4.6
FreedesktopDbus Version1.4.8
FreedesktopDbus Version1.4.10
FreedesktopDbus Version1.4.12
FreedesktopDbus Version1.4.14
FreedesktopDbus Version1.4.16
FreedesktopDbus Version1.4.18
FreedesktopDbus Version1.4.20
FreedesktopDbus Version1.4.24
FreedesktopDbus Version1.7.0
FreedesktopDbus Version1.7.2
FreedesktopDbus Version1.6.0
FreedesktopDbus Version1.6.2
FreedesktopDbus Version1.6.4
FreedesktopDbus Version1.6.6
FreedesktopDbus Version1.6.8
FreedesktopDbus Version1.6.10
FreedesktopDbus Version1.6.16
OpensuseOpensuse Version12.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.236
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 1.9 3.4 2.9
AV:L/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.