First published: Tue Nov 18 2014(Updated: )
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Freedesktop D-Bus | =1.6.0 | |
Freedesktop D-Bus | =1.6.2 | |
Freedesktop D-Bus | =1.6.4 | |
Freedesktop D-Bus | =1.6.6 | |
Freedesktop D-Bus | =1.6.8 | |
Freedesktop D-Bus | =1.6.10 | |
Freedesktop D-Bus | =1.6.12 | |
Freedesktop D-Bus | =1.6.14 | |
Freedesktop D-Bus | =1.6.16 | |
Freedesktop D-Bus | =1.6.18 | |
Freedesktop D-Bus | =1.6.20 | |
Freedesktop D-Bus | =1.6.22 | |
Freedesktop D-Bus | =1.6.24 | |
Freedesktop D-Bus | =1.8.0 | |
Freedesktop D-Bus | =1.8.2 | |
Freedesktop D-Bus | =1.8.4 | |
Freedesktop D-Bus | =1.8.6 | |
Freedesktop D-Bus | =1.8.8 | |
Freedesktop D-Bus | =1.9.0 | |
Debian | =7.0 | |
Debian | =8.0 | |
Mageia | =3 | |
Mageia | =4 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =14.10 | |
dbus | =1.6.0 | |
dbus | =1.6.2 | |
dbus | =1.6.4 | |
dbus | =1.6.6 | |
dbus | =1.6.8 | |
dbus | =1.6.10 | |
dbus | =1.6.12 | |
dbus | =1.6.14 | |
dbus | =1.6.16 | |
dbus | =1.6.18 | |
dbus | =1.6.20 | |
dbus | =1.6.22 | |
dbus | =1.6.24 | |
dbus | =1.8.0 | |
dbus | =1.8.2 | |
dbus | =1.8.4 | |
dbus | =1.8.6 | |
dbus | =1.8.8 | |
dbus | =1.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7824 is classified as a denial of service vulnerability that affects local users of D-Bus.
To mitigate CVE-2014-7824, update D-Bus to a version higher than 1.6.26, 1.8.10, or 1.9.2.
CVE-2014-7824 affects D-Bus versions 1.3.0 through 1.6.x (before 1.6.26), 1.8.x (before 1.8.10), and 1.9.x (before 1.9.2).
No, CVE-2014-7824 is a local vulnerability that requires local access to exploit.
CVE-2014-7824 can lead to denial of service by preventing new connections and dropping existing ones, impacting system availability.