FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2014-3532

This CVE name corresponds to:

Entered Topic
2014-07-03 dbus -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2014-3532
Phase Assigned(20140514)

Description

dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.

References

Source Reference
MLIST [oss-security] 20140702 CVE-2014-3532, -3533: two local DoS vulnerabilities in dbus-daemon
CONFIRM https://bugs.freedesktop.org/show_bug.cgi?id=80163
CONFIRM http://advisories.mageia.org/MGASA-2014-0294.html
DEBIAN DSA-2971
MANDRIVA MDVSA-2015:176
SUSE openSUSE-SU-2014:1239
SECUNIA 59611
SECUNIA 59798
SECUNIA 60236