The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-native byte order, which allows local users to cause a denial of service (connection loss), obtain potentially sensitive information, or conduct unspecified state-modification attacks via crafted messages.
CVSS Details
- CVSS 3.1 Base Score: 5.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade dbusUpgrade dbus-x11Upgrade dbus-libsUpgrade dbus-devel | Dec 1, 2016 | Jun 22, 2011 |
| Debian | — | Upgrade dbus | Jul 30, 2024 | Jun 22, 2011 |
| Gentoo Linux | — | Upgrade sys-apps/dbus. | Oct 30, 2017 | Jun 22, 2011 |
| Oracle_linux | — | Upgrade dbus-x11Upgrade dbus-docUpgrade dbus-develUpgrade dbusUpgrade dbus-libs | Oct 16, 2024 | Jun 22, 2011 |
| Suse | — | Upgrade dbus-1-devel-docUpgrade sap-aio-releaseUpgrade dbus-1-develUpgrade dbus-1-32bitUpgrade dbus-1Upgrade dbus-1-x86Upgrade dbus-1-devel-32bitUpgrade dbus-1-glib-32bitUpgrade dbus-1-glib-x86Upgrade dbus-1-glib-64bitUpgrade dbus-1-64bitUpgrade dbus-1-glib | Dec 12, 2013 | Jun 22, 2011 |
| Ubuntu | — | Upgrade dbus | Nov 8, 2024 | Jun 22, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub