D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
2014-11-18T15:59:04.017
2025-04-12T10:46:40.837
Deferred
CVSSv2: 2.1 (LOW)
AV:L/AC:L/Au:N/C:N/I:N/A:P
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | freedesktop | dbus | 1.6.0 | Yes |
| Application | freedesktop | dbus | 1.6.2 | Yes |
| Application | freedesktop | dbus | 1.6.4 | Yes |
| Application | freedesktop | dbus | 1.6.6 | Yes |
| Application | freedesktop | dbus | 1.6.8 | Yes |
| Application | freedesktop | dbus | 1.6.10 | Yes |
| Application | freedesktop | dbus | 1.6.12 | Yes |
| Application | freedesktop | dbus | 1.6.14 | Yes |
| Application | freedesktop | dbus | 1.6.16 | Yes |
| Application | freedesktop | dbus | 1.6.18 | Yes |
| Application | freedesktop | dbus | 1.6.20 | Yes |
| Application | freedesktop | dbus | 1.6.22 | Yes |
| Application | freedesktop | dbus | 1.6.24 | Yes |
| Application | freedesktop | dbus | 1.8.0 | Yes |
| Application | freedesktop | dbus | 1.8.2 | Yes |
| Application | freedesktop | dbus | 1.8.4 | Yes |
| Application | freedesktop | dbus | 1.8.6 | Yes |
| Application | freedesktop | dbus | 1.8.8 | Yes |
| Application | freedesktop | dbus | 1.9.0 | Yes |
| Operating System | debian | debian_linux | 7.0 | Yes |
| Operating System | debian | debian_linux | 8.0 | Yes |
| Operating System | mageia_project | mageia | 3 | Yes |
| Operating System | mageia_project | mageia | 4 | Yes |
| Operating System | canonical | ubuntu_linux | 12.04 | Yes |
| Operating System | canonical | ubuntu_linux | 14.04 | Yes |
| Operating System | canonical | ubuntu_linux | 14.10 | Yes |