First published: Tue Jul 01 2014(Updated: )
The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D-Bus message to an inactive service.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.2.4.2 | ||
=1.2.4.4 | ||
=1.2.4.6 | ||
=1.2.1 | ||
=1.2.3 | ||
=1.2.4 | ||
=1.2.6 | ||
=1.2.8 | ||
=1.2.10 | ||
=1.2.12 | ||
=1.2.14 | ||
=1.2.16 | ||
=1.2.18 | ||
=1.2.20 | ||
=1.2.22 | ||
=1.2.24 | ||
=1.2.26 | ||
=1.2.28 | ||
=1.2.30 | ||
=1.3.0 | ||
=1.3.1 | ||
=1.4.0 | ||
=1.4.1 | ||
=1.4.4 | ||
=1.4.6 | ||
=1.4.8 | ||
=1.4.10 | ||
=1.4.12 | ||
=1.4.14 | ||
=1.4.16 | ||
=1.4.18 | ||
=1.4.20 | ||
=1.4.22 | ||
=1.4.24 | ||
=1.4.26 | ||
=1.6.0 | ||
=1.6.2 | ||
=1.6.4 | ||
=1.6.6 | ||
=1.6.8 | ||
=1.6.10 | ||
=1.6.12 | ||
=1.6.14 | ||
=1.6.16 | ||
=1.6.18 | ||
=1.8.0 | ||
=1.8.2 | ||
D-bus Project D-bus | =1.2.1 | |
D-bus Project D-bus | =1.2.3 | |
D-bus Project D-bus | =1.2.4 | |
D-bus Project D-bus | =1.2.4.2 | |
D-bus Project D-bus | =1.2.4.4 | |
D-bus Project D-bus | =1.2.4.6 | |
D-bus Project D-bus | =1.2.6 | |
D-bus Project D-bus | =1.2.8 | |
D-bus Project D-bus | =1.2.10 | |
D-bus Project D-bus | =1.2.12 | |
D-bus Project D-bus | =1.2.14 | |
D-bus Project D-bus | =1.2.16 | |
D-bus Project D-bus | =1.2.18 | |
D-bus Project D-bus | =1.2.20 | |
D-bus Project D-bus | =1.2.22 | |
D-bus Project D-bus | =1.2.24 | |
D-bus Project D-bus | =1.2.26 | |
D-bus Project D-bus | =1.2.28 | |
D-bus Project D-bus | =1.2.30 | |
D-bus Project D-bus | =1.3.0 | |
D-bus Project D-bus | =1.3.1 | |
D-bus Project D-bus | =1.4.0 | |
D-bus Project D-bus | =1.4.1 | |
D-bus Project D-bus | =1.4.4 | |
D-bus Project D-bus | =1.4.6 | |
D-bus Project D-bus | =1.4.8 | |
D-bus Project D-bus | =1.4.10 | |
D-bus Project D-bus | =1.4.12 | |
D-bus Project D-bus | =1.4.14 | |
D-bus Project D-bus | =1.4.16 | |
D-bus Project D-bus | =1.4.18 | |
D-bus Project D-bus | =1.4.20 | |
D-bus Project D-bus | =1.4.22 | |
D-bus Project D-bus | =1.4.24 | |
D-bus Project D-bus | =1.4.26 | |
D-bus Project D-bus | =1.6.0 | |
D-bus Project D-bus | =1.6.2 | |
D-bus Project D-bus | =1.6.4 | |
D-bus Project D-bus | =1.6.6 | |
D-bus Project D-bus | =1.6.8 | |
D-bus Project D-bus | =1.6.10 | |
D-bus Project D-bus | =1.6.12 | |
D-bus Project D-bus | =1.6.14 | |
D-bus Project D-bus | =1.6.16 | |
D-bus Project D-bus | =1.6.18 | |
D-bus Project D-bus | =1.8.0 | |
D-bus Project D-bus | =1.8.2 |
http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.8&id=24c590703ca47eb71ddef453de43126b90954567
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.