CVE-2014-3477: Medium severity dbus vulnerability
The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D-Bus message to an inactive service.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3477?
The severity of CVE-2014-3477 is considered moderate due to its potential to cause a denial of service.
How do I fix CVE-2014-3477?
Fix CVE-2014-3477 by upgrading D-Bus to versions 1.6.20 or later, or 1.8.4 or later.
Who is affected by CVE-2014-3477?
CVE-2014-3477 affects local users of D-Bus versions 1.2.x through 1.4.x, earlier than 1.6.20, and 1.8.x earlier than 1.8.4.
What kind of attack does CVE-2014-3477 allow?
CVE-2014-3477 allows local users to trigger a denial of service by causing an initialization failure in the dbus-daemon.
Is there a workaround for CVE-2014-3477?
No official workaround is available for CVE-2014-3477; the recommended mitigation is to update to a patched version.