CVE-2014-3532
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.0012 (0.1%)
Percentil: 30.9%
EPSS: 2026-05-06
Afecta
freedesktop:dbuslinux:linux_kernelopensuse:opensusedebian:debian_linuxmageia:mageiaoracle:solarisDescripción técnica
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.
Publicada: 19/7/2014, 19:55:07
Última modificación: 6/5/2026, 22:30:45
Referencias
- http://advisories.mageia.org/MGASA-2014-0294.html
- http://lists.opensuse.org/opensuse-updates/2014-09/msg00049.html
- http://openwall.com/lists/oss-security/2014/07/02/4
- http://secunia.com/advisories/59611
- http://secunia.com/advisories/59798
- http://secunia.com/advisories/60236
- http://www.debian.org/security/2014/dsa-2971
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:176