vendor:
D-Bus
by:
Jon Oberheide
7.8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: D-Bus
Affected Version From: < 1.2.4
Affected Version To: 1.2.2004
Patch Exists: YES
Related CWE: CVE-2008-3834
CPE: a:freedesktop:dbus
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ubuntu-USN-799-1/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2009-1189/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2009-1189/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2008-3834/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2008-3834/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2008-3834/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-ELSA-2010-0018/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-0008/
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=53590, https://www.infosecmatter.com/nessus-plugin-library/?id=35317, https://www.infosecmatter.com/nessus-plugin-library/?id=35034, https://www.infosecmatter.com/nessus-plugin-library/?id=39947, https://www.infosecmatter.com/nessus-plugin-library/?id=36805, https://www.infosecmatter.com/nessus-plugin-library/?id=34381, https://www.infosecmatter.com/nessus-plugin-library/?id=34437, https://www.infosecmatter.com/nessus-plugin-library/?id=67785, https://www.infosecmatter.com/nessus-plugin-library/?id=43724, https://www.infosecmatter.com/nessus-plugin-library/?id=34478
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2008
D-Bus Daemon Denial of Service < 1.2.4
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.
Mitigation:
Upgrade to D-Bus library version 1.2.4 or later.