CVE-2014-7824: Low severity freedesktop d-bus vulnerability
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7824?
CVE-2014-7824 is classified as a denial of service vulnerability that affects local users of D-Bus.
How do I fix CVE-2014-7824?
To mitigate CVE-2014-7824, update D-Bus to a version higher than 1.6.26, 1.8.10, or 1.9.2.
What software is affected by CVE-2014-7824?
CVE-2014-7824 affects D-Bus versions 1.3.0 through 1.6.x (before 1.6.26), 1.8.x (before 1.8.10), and 1.9.x (before 1.9.2).
Can CVE-2014-7824 be exploited remotely?
No, CVE-2014-7824 is a local vulnerability that requires local access to exploit.
What impact does CVE-2014-7824 have on system performance?
CVE-2014-7824 can lead to denial of service by preventing new connections and dropping existing ones, impacting system availability.