CVE-2014-3532

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
19/07/2014
Last modified:
12/04/2025

Description

dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:* 1.3.0 (including) 1.6.22 (excluding)
cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:* 1.8.0 (including) 1.8.6 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.38 (including)
cpe:2.3:o:linux:linux_kernel:2.6.37:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.37:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.37:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.37:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.37:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.37:rc8:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:mageia:mageia:3.0:*:*:*:*:*:*:*
cpe:2.3:o:mageia:mageia:4.0:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*