4.6
CVSSv2

CVE-2011-2200

Published: 22/06/2011 Updated: 27/12/2023
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x prior to 1.2.28, 1.4.x prior to 1.4.12, and 1.5.x prior to 1.5.4 does not properly handle a non-native byte order, which allows local users to cause a denial of service (connection loss), obtain potentially sensitive information, or conduct unspecified state-modification attacks via crafted messages.

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop dbus 1.5.0

freedesktop dbus 1.5.2

freedesktop dbus 1.4.6

freedesktop dbus 1.4.8

freedesktop dbus 1.4.1

freedesktop dbus 1.4.0

freedesktop dbus 1.4.10

freedesktop dbus 1.4.4

d-bus project d-bus 1.2.4.2

d-bus project d-bus 1.2.4.4

freedesktop dbus 1.2.26

freedesktop dbus 1.2.20

freedesktop dbus 1.2.4

freedesktop dbus 1.2.1

freedesktop dbus 1.2.10

freedesktop dbus 1.2.6

freedesktop dbus 1.2.24

freedesktop dbus 1.2.22

freedesktop dbus 1.2.18

freedesktop dbus 1.2.8

freedesktop dbus 1.2.16

d-bus project d-bus 1.2.4.6

freedesktop dbus 1.2.12

freedesktop dbus 1.2.3

freedesktop dbus 1.2.14

freedesktop dbus 1.2.2

Vendor Advisories

Debian Bug report logs - #629938 libdbus-1-3: [CVE-2011-2200] local DoS via messages with non-native byte order Package: libdbus-1-3; Maintainer for libdbus-1-3 is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Source for libdbus-1-3 is src:dbus (PTS, buildd, popcon) Reported by: Simon McVittie &lt ...
DBus could be made to crash if it processed a specially crafted message ...