First published: Mon Jun 08 2020(Updated: )
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Freedesktop Dbus | >=1.3.0<1.12.18 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Canonical Ubuntu Linux | =20.04 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.2.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.1.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.0.0 | |
ubuntu/dbus | <1.12.2-1ubuntu1.2 | 1.12.2-1ubuntu1.2 |
ubuntu/dbus | <1.12.14-1ubuntu2.1 | 1.12.14-1ubuntu2.1 |
ubuntu/dbus | <1.12.16-2ubuntu2.1 | 1.12.16-2ubuntu2.1 |
ubuntu/dbus | <1.6.18-0ubuntu4.5+ | 1.6.18-0ubuntu4.5+ |
ubuntu/dbus | <1.12.18<1.10.30 | 1.12.18 1.10.30 |
ubuntu/dbus | <1.10.6-1ubuntu3.6 | 1.10.6-1ubuntu3.6 |
debian/dbus | 1.12.28-0+deb11u1 1.12.24-0+deb11u1 1.14.10-1~deb12u1 1.14.10-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12049 is a vulnerability in D-Bus that can be exploited to cause a denial of service.
CVE-2020-12049 can result in a denial of service by leaking file descriptors when a message exceeds the per-message file descriptor limit.
The severity of CVE-2020-12049 is medium, with a severity value of 5.5.
To fix CVE-2020-12049, update to the recommended versions of D-Bus provided by your operating system or package manager.
You can find more information about CVE-2020-12049 in the references provided: [link 1](http://packetstormsecurity.com/files/172840/D-Bus-File-Descriptor-Leak-Denial-Of-Service.html), [link 2](http://www.openwall.com/lists/oss-security/2020/06/04/3), [link 3](https://gitlab.freedesktop.org/dbus/dbus/-/issues/294).