Bug 1114414 (CVE-2014-3532)

Summary: CVE-2014-3532 dbus: denial of service in file descriptor passing feature
Product: [Other] Security Response Reporter: Murray McAllister <mmcallis>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: carnil, rhughes, security-response-team, sisharma, walters
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: dbus 1.6.22, dbus 1.8.6 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-08-24 09:37:17 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1115636, 1115637, 1115638    
Bug Blocks: 1114417    

Description Murray McAllister 2014-06-30 03:26:41 UTC
A flaw was reported in D-Bus's file descriptor passing feature. A local attacker could use this flaw to cause a service or application to disconnect from the bus, typically resulting in that service or application exiting.

It is reported that versions 1.3.0 and newer are affected.

Acknowledgements:

Red Hat would like to thank D-Bus upstream for reporting this issue. Upstream acknowledges Alban Crequy of Collabora Ltd. as the original reporter.

Comment 2 Vincent Danen 2014-07-02 19:41:00 UTC
This is now public:

http://openwall.com/lists/oss-security/2014/07/02/4

Comment 3 Vincent Danen 2014-07-02 19:44:53 UTC
Created dbus tracking bugs for this issue:

Affects: fedora-all [bug 1115636]

Comment 4 Vincent Danen 2014-07-02 19:44:55 UTC
Created mingw-dbus tracking bugs for this issue:

Affects: fedora-all [bug 1115637]
Affects: epel-7 [bug 1115638]

Comment 5 Fedora Update System 2014-07-08 01:04:32 UTC
dbus-1.6.12-9.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.