CVE-2014-3637: Low severity freedesktop d-bus vulnerability
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections for processes that have terminated, which allows local users to cause a denial of service via a D-bus message containing a D-Bus connection file descriptor.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3637?
CVE-2014-3637 has a medium severity rating due to its potential to allow local users to cause denial of service.
How do I fix CVE-2014-3637?
To mitigate CVE-2014-3637, upgrade D-Bus to version 1.6.24 or later or 1.8.8 or later.
What versions are affected by CVE-2014-3637?
CVE-2014-3637 affects D-Bus versions from 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8.
What type of vulnerability is CVE-2014-3637?
CVE-2014-3637 is a local denial of service vulnerability related to improper connection handling in D-Bus.
Can CVE-2014-3637 be exploited remotely?
CVE-2014-3637 cannot be exploited remotely as it requires local user access to trigger the vulnerability.