2.1
CVE-2014-3532
- EPSS 0.45%
- Veröffentlicht 19.07.2014 19:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freedesktop ≫ Dbus Version >= 1.3.0 < 1.6.22
Linux ≫ Linux Kernel Version >= 2.6.38
Linux ≫ Linux Kernel Version 2.6.37 Update -
Linux ≫ Linux Kernel Version 2.6.37 Update rc4
Linux ≫ Linux Kernel Version 2.6.37 Update rc5
Linux ≫ Linux Kernel Version 2.6.37 Update rc6
Linux ≫ Linux Kernel Version 2.6.37 Update rc7
Linux ≫ Linux Kernel Version 2.6.37 Update rc8
Linux ≫ Linux Kernel Version 2.6.37 Update -
Linux ≫ Linux Kernel Version 2.6.37 Update rc4
Linux ≫ Linux Kernel Version 2.6.37 Update rc5
Linux ≫ Linux Kernel Version 2.6.37 Update rc6
Linux ≫ Linux Kernel Version 2.6.37 Update rc7
Linux ≫ Linux Kernel Version 2.6.37 Update rc8
Freedesktop ≫ Dbus Version >= 1.8.0 < 1.8.6
Linux ≫ Linux Kernel Version >= 2.6.38
Linux ≫ Linux Kernel Version 2.6.37 Update -
Linux ≫ Linux Kernel Version 2.6.37 Update rc4
Linux ≫ Linux Kernel Version 2.6.37 Update rc5
Linux ≫ Linux Kernel Version 2.6.37 Update rc6
Linux ≫ Linux Kernel Version 2.6.37 Update rc7
Linux ≫ Linux Kernel Version 2.6.37 Update rc8
Linux ≫ Linux Kernel Version 2.6.37 Update -
Linux ≫ Linux Kernel Version 2.6.37 Update rc4
Linux ≫ Linux Kernel Version 2.6.37 Update rc5
Linux ≫ Linux Kernel Version 2.6.37 Update rc6
Linux ≫ Linux Kernel Version 2.6.37 Update rc7
Linux ≫ Linux Kernel Version 2.6.37 Update rc8
Debian ≫ Debian Linux Version 7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.45% | 0.354 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
http://lists.opensuse.org/opensuse-updates/2014-09/msg00049.html
http://secunia.com/advisories/59611
http://secunia.com/advisories/59798
http://www.debian.org/security/2014/dsa-2971
http://www.mandriva.com/security/advisories?name=MDVSA-2015:176
http://advisories.mageia.org/MGASA-2014-0294.html
http://openwall.com/lists/oss-security/2014/07/02/4
http://secunia.com/advisories/60236
https://bugs.freedesktop.org/show_bug.cgi?id=80163