dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.
2014-07-19T19:55:07.950
2025-04-12T10:46:40.837
Deferred
CVSSv2: 2.1 (LOW)
AV:L/AC:L/Au:N/C:N/I:N/A:P
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | freedesktop | dbus | < 1.6.22 | Yes |
Application | freedesktop | dbus | < 1.8.6 | Yes |
Operating System | linux | linux_kernel | ≥ 2.6.38 | No |
Operating System | linux | linux_kernel | 2.6.37 | No |
Operating System | linux | linux_kernel | 2.6.37 | No |
Operating System | linux | linux_kernel | 2.6.37 | No |
Operating System | linux | linux_kernel | 2.6.37 | No |
Operating System | linux | linux_kernel | 2.6.37 | No |
Operating System | linux | linux_kernel | 2.6.37 | No |
Operating System | opensuse | opensuse | 12.3 | Yes |
Operating System | debian | debian_linux | 7.0 | Yes |
Operating System | mageia | mageia | 3.0 | Yes |
Operating System | mageia | mageia | 4.0 | Yes |
Operating System | oracle | solaris | 11.3 | Yes |