Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-34969


D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.


Published

2023-06-08T03:15:08.970

Last Modified

2025-06-09T15:15:29.340

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-404

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application freedesktop dbus < 1.12.28 Yes
Application freedesktop dbus < 1.14.8 Yes
Application freedesktop dbus < 1.15.6 Yes
Operating System fedoraproject fedora 38 Yes
Operating System debian debian_linux 10.0 Yes

References