USN-2275-1
Dashboard / Vulnerabilities / USN-2275-1
USN-2275-1
Summary: dbus vulnerabilities
Details: Alban Crequy discovered that dbus-daemon incorrectly sent AccessDenied errors to the service instead of the client when enforcing permissions. A local user can use this issue to possibly deny access to the service. (CVE-2014-3477) Alban Crequy discovered that dbus-daemon incorrectly handled certain file descriptors. A local attacker could use this issue to cause services or clients to disconnect, resulting in a denial of service. (CVE-2014-3532, CVE-2014-3533)
References: https://ubuntu.com/security/notices/USN-2275-1, https://ubuntu.com/security/CVE-2014-3477, https://ubuntu.com/security/CVE-2014-3532, https://ubuntu.com/security/CVE-2014-3533
Affected packages
Package
Name: dbus
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
