← Back

CVE-2014-3635

nvd nist
Published: Sep 22, 2014Modified: May 6, 2026

JSON object

Loading...
4.4
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 3.4 / Impact: 6.4
Source: NVD

Description

Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows local users to cause a denial of service (dbus-daemon crash) or possibly execute arbitrary code by sending one more file descriptor than the limit, which triggers a heap-based buffer overflow or an assertion failure.

Affected (17)

1 product
D Bus
1 product
Dbus
1 product
Opensuse
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.6.22
Freedesktop
Version 1.6.0
Version 1.6.10
Version 1.6.12
Version 1.6.14
Version 1.6.16
Version 1.6.18
Version 1.6.20
Version 1.6.2
Version 1.6.4
Version 1.6.6
Version 1.6.8
Version 1.8.0
Version 1.8.2
Version 1.8.4
Version 1.8.6
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.3

References (20)

Source: secalert@redhat.com
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

Timeline

No history available yet.