CVE-2014-7824
Published: 18 November 2014
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
Notes
Author | Note |
---|---|
mdeslaur | also should include regression fix for CVE-2014-3639: https://bugs.freedesktop.org/show_bug.cgi?id=86431 |
Priority
Status
Package | Release | Status |
---|---|---|
dbus Launchpad, Ubuntu, Debian |
upstream |
Released
(1.6.26, 1.8.10-1)
|
lucid |
Not vulnerable
(1.2.16-2ubuntu4.7)
|
|
precise |
Released
(1.4.18-1ubuntu1.7)
|
|
trusty |
Released
(1.6.18-0ubuntu4.3)
|
|
utopic |
Released
(1.8.8-1ubuntu2.1)
|
|
Patches: upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.6&id=68cb9ead957314b30e604018f2dd5b0fc3b2127c (1.6) upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.8&id=4e466446d27f1a3991c22307a47a81c9e93e530d (1.8) |