First published: Tue Jul 01 2014(Updated: )
The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D-Bus message to an inactive service.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
dbus | =1.2.4.2 | |
dbus | =1.2.4.4 | |
dbus | =1.2.4.6 | |
Freedesktop D-Bus | =1.2.1 | |
Freedesktop D-Bus | =1.2.3 | |
Freedesktop D-Bus | =1.2.4 | |
Freedesktop D-Bus | =1.2.6 | |
Freedesktop D-Bus | =1.2.8 | |
Freedesktop D-Bus | =1.2.10 | |
Freedesktop D-Bus | =1.2.12 | |
Freedesktop D-Bus | =1.2.14 | |
Freedesktop D-Bus | =1.2.16 | |
Freedesktop D-Bus | =1.2.18 | |
Freedesktop D-Bus | =1.2.20 | |
Freedesktop D-Bus | =1.2.22 | |
Freedesktop D-Bus | =1.2.24 | |
Freedesktop D-Bus | =1.2.26 | |
Freedesktop D-Bus | =1.2.28 | |
Freedesktop D-Bus | =1.2.30 | |
Freedesktop D-Bus | =1.3.0 | |
Freedesktop D-Bus | =1.3.1 | |
Freedesktop D-Bus | =1.4.0 | |
Freedesktop D-Bus | =1.4.1 | |
Freedesktop D-Bus | =1.4.4 | |
Freedesktop D-Bus | =1.4.6 | |
Freedesktop D-Bus | =1.4.8 | |
Freedesktop D-Bus | =1.4.10 | |
Freedesktop D-Bus | =1.4.12 | |
Freedesktop D-Bus | =1.4.14 | |
Freedesktop D-Bus | =1.4.16 | |
Freedesktop D-Bus | =1.4.18 | |
Freedesktop D-Bus | =1.4.20 | |
Freedesktop D-Bus | =1.4.22 | |
Freedesktop D-Bus | =1.4.24 | |
Freedesktop D-Bus | =1.4.26 | |
Freedesktop D-Bus | =1.6.0 | |
Freedesktop D-Bus | =1.6.2 | |
Freedesktop D-Bus | =1.6.4 | |
Freedesktop D-Bus | =1.6.6 | |
Freedesktop D-Bus | =1.6.8 | |
Freedesktop D-Bus | =1.6.10 | |
Freedesktop D-Bus | =1.6.12 | |
Freedesktop D-Bus | =1.6.14 | |
Freedesktop D-Bus | =1.6.16 | |
Freedesktop D-Bus | =1.6.18 | |
Freedesktop D-Bus | =1.8.0 | |
Freedesktop D-Bus | =1.8.2 | |
dbus | =1.2.1 | |
dbus | =1.2.3 | |
dbus | =1.2.4 | |
dbus | =1.2.6 | |
dbus | =1.2.8 | |
dbus | =1.2.10 | |
dbus | =1.2.12 | |
dbus | =1.2.14 | |
dbus | =1.2.16 | |
dbus | =1.2.18 | |
dbus | =1.2.20 | |
dbus | =1.2.22 | |
dbus | =1.2.24 | |
dbus | =1.2.26 | |
dbus | =1.2.28 | |
dbus | =1.2.30 | |
dbus | =1.3.0 | |
dbus | =1.3.1 | |
dbus | =1.4.0 | |
dbus | =1.4.1 | |
dbus | =1.4.4 | |
dbus | =1.4.6 | |
dbus | =1.4.8 | |
dbus | =1.4.10 | |
dbus | =1.4.12 | |
dbus | =1.4.14 | |
dbus | =1.4.16 | |
dbus | =1.4.18 | |
dbus | =1.4.20 | |
dbus | =1.4.22 | |
dbus | =1.4.24 | |
dbus | =1.4.26 | |
dbus | =1.6.0 | |
dbus | =1.6.2 | |
dbus | =1.6.4 | |
dbus | =1.6.6 | |
dbus | =1.6.8 | |
dbus | =1.6.10 | |
dbus | =1.6.12 | |
dbus | =1.6.14 | |
dbus | =1.6.16 | |
dbus | =1.6.18 | |
dbus | =1.8.0 | |
dbus | =1.8.2 |
http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.8&id=24c590703ca47eb71ddef453de43126b90954567
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-3477 is considered moderate due to its potential to cause a denial of service.
Fix CVE-2014-3477 by upgrading D-Bus to versions 1.6.20 or later, or 1.8.4 or later.
CVE-2014-3477 affects local users of D-Bus versions 1.2.x through 1.4.x, earlier than 1.6.20, and 1.8.x earlier than 1.8.4.
CVE-2014-3477 allows local users to trigger a denial of service by causing an initialization failure in the dbus-daemon.
No official workaround is available for CVE-2014-3477; the recommended mitigation is to update to a patched version.