1.9
CVSSv2

CVE-2015-0245

Published: 13/02/2015 Updated: 27/12/2023
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

D-Bus 1.4.x up to and including 1.6.x prior to 1.6.30, 1.8.x prior to 1.8.16, and 1.9.x prior to 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before systemd responds.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop dbus 1.6.4

freedesktop dbus 1.4.18

freedesktop dbus 1.6.0

freedesktop dbus 1.5.6

freedesktop dbus 1.6.24

freedesktop dbus 1.8.0

freedesktop dbus 1.5.8

freedesktop dbus 1.5.4

freedesktop dbus 1.5.10

freedesktop dbus 1.9.0

freedesktop dbus 1.4.24

freedesktop dbus 1.4.12

freedesktop dbus 1.6.20

freedesktop dbus 1.6.10

freedesktop dbus 1.5.0

freedesktop dbus 1.6.12

freedesktop dbus 1.6.16

freedesktop dbus 1.4.6

freedesktop dbus 1.6.8

freedesktop dbus 1.4.16

freedesktop dbus 1.5.2

freedesktop dbus 1.6.26

freedesktop dbus 1.9.6

freedesktop dbus 1.4.8

freedesktop dbus 1.9.2

freedesktop dbus 1.6.14

freedesktop dbus 1.4.14

freedesktop dbus 1.4.1

freedesktop dbus 1.6.6

freedesktop dbus 1.6.22

freedesktop dbus 1.8.6

freedesktop dbus 1.6.18

freedesktop dbus 1.4.0

freedesktop dbus 1.9.8

freedesktop dbus 1.6.28

freedesktop dbus 1.8.8

freedesktop dbus 1.8.12

freedesktop dbus 1.9.4

freedesktop dbus 1.8.14

freedesktop dbus 1.8.4

freedesktop dbus 1.4.20

freedesktop dbus 1.4.26

freedesktop dbus 1.8.2

freedesktop dbus 1.4.10

freedesktop dbus 1.4.4

freedesktop dbus 1.8.10

freedesktop dbus 1.5.12

freedesktop dbus 1.6.2

opensuse opensuse 13.1

opensuse opensuse 13.2

Vendor Advisories

Debian Bug report logs - #777545 CVE-2015-0245: denial of service in dbus >= 14 Package: dbus; Maintainer for dbus is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Source for dbus is src:dbus (PTS, buildd, popcon) Reported by: Simon McVittie <smcv@debianorg> Date: Mon, 9 Feb 2015 15: ...
Several security issues were fixed in DBus ...
Simon McVittie discovered a local denial of service flaw in dbus, an asynchronous inter-process communication system On systems with systemd-style service activation, dbus-daemon does not prevent forged ActivationFailure messages from non-root processes A malicious local user could use this flaw to trick dbus-daemon into thinking that systemd fai ...