ubuntu · CVE-2014-3532

Quick triage

Priority: medium Published: 2014-07-02 00:00:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2014-3532 medium priority: Ubuntu including 1 source packages (dbus), 5 status rows across 5 suites (lucid, precise, saucy, trusty, upstream): released 4, not-affected 1.

Description:

dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.

cvelogic Threat Intelligence