CVE-2015-0245: Race Condition
D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before systemd responds.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0245?
CVE-2015-0245 is categorized as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2015-0245?
To fix CVE-2015-0245, it is recommended to upgrade to D-Bus version 1.6.30 or higher, or 1.8.16 or higher, or 1.9.10 or higher.
Which versions are affected by CVE-2015-0245?
CVE-2015-0245 affects D-Bus versions from 1.4.x to 1.6.x before 1.6.30, as well as 1.8.x before 1.8.16 and 1.9.x before 1.9.10.
What type of attack is possible with CVE-2015-0245?
CVE-2015-0245 can be exploited locally by users to trigger a denial of service through ActivationFailure signals.
What software is impacted by CVE-2015-0245?
CVE-2015-0245 impacts D-Bus software specifically in versions listed between 1.4.0 and 1.9.8 across various distributions.