2.1
CVSSv2

CVE-2010-4352

Published: 30/12/2010 Updated: 08/12/2016
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Stack consumption vulnerability in D-Bus (aka DBus) prior to 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants.

Vulnerable Product Search on Vulmon Subscribe to Product

d-bus project d-bus

Vendor Advisories

A local attacker could send crafted input to D-Bus and cause it to crash ...
Rémi Denis-Courmont discovered that dbus, a message bus application, is not properly limiting the nesting level when examining messages with extensive nested variants This allows an attacker to crash the dbus system daemon due to a call stack overflow via crafted messages For the stable distribution (lenny), this problem has been fixed in versio ...