CVE-2014-3532: Input Validation
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3532?
CVE-2014-3532 has a severity rating that indicates it can cause denial of service issues on affected systems.
How do I fix CVE-2014-3532?
To mitigate CVE-2014-3532, upgrade D-Bus to version 1.6.22 or later for versions prior to 1.6.22, and to version 1.8.6 or later for 1.8.x versions.
What versions of D-Bus are affected by CVE-2014-3532?
CVE-2014-3532 affects D-Bus versions between 1.3.0 and 1.6.22 as well as versions between 1.8.0 and 1.8.6.
Which operating systems are vulnerable to CVE-2014-3532?
CVE-2014-3532 impacts various operating systems including openSUSE 12.3, Debian 7.0, and Mageia 3.0 and 4.0.
What types of attacks can exploit CVE-2014-3532?
Exploitation of CVE-2014-3532 could allow local users to disrupt system bus connections, leading to denial of service for other services or applications.