2.1
CVSSv2

CVE-2014-3477

Published: 01/07/2014 Updated: 27/12/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The dbus-daemon in D-Bus 1.2.x up to and including 1.4.x, 1.6.x prior to 1.6.20, and 1.8.x prior to 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D-Bus message to an inactive service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop dbus 1.2.26

freedesktop dbus 1.2.20

freedesktop dbus 1.2.4

freedesktop dbus 1.2.1

freedesktop dbus 1.2.10

freedesktop dbus 1.2.6

freedesktop dbus 1.2.24

freedesktop dbus 1.2.22

d-bus project d-bus 1.2.4.6

freedesktop dbus 1.2.18

freedesktop dbus 1.2.8

d-bus project d-bus 1.2.4.2

freedesktop dbus 1.2.16

freedesktop dbus 1.2.12

freedesktop dbus 1.2.3

freedesktop dbus 1.2.14

d-bus project d-bus 1.2.4.4

freedesktop dbus 1.6.4

freedesktop dbus 1.4.18

freedesktop dbus 1.6.0

freedesktop dbus 1.4.22

freedesktop dbus 1.2.30

freedesktop dbus 1.8.0

freedesktop dbus 1.4.24

freedesktop dbus 1.4.12

freedesktop dbus 1.6.10

freedesktop dbus 1.6.12

freedesktop dbus 1.6.16

freedesktop dbus 1.4.6

freedesktop dbus 1.6.8

freedesktop dbus 1.4.16

freedesktop dbus 1.3.0

freedesktop dbus 1.4.8

freedesktop dbus 1.3.1

freedesktop dbus 1.6.14

freedesktop dbus 1.4.14

freedesktop dbus 1.2.28

freedesktop dbus 1.4.1

freedesktop dbus 1.6.6

freedesktop dbus 1.6.18

freedesktop dbus 1.4.0

freedesktop dbus 1.4.20

freedesktop dbus 1.4.26

freedesktop dbus 1.8.2

freedesktop dbus 1.4.10

freedesktop dbus 1.4.4

freedesktop dbus 1.6.2

Vendor Advisories

Several security issues were fixed in DBus ...
The dbus-daemon in D-Bus 12x through 14x, 16x before 1620, and 18x before 184, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D- ...