Bug 1140523 (CVE-2014-3635)

Summary: CVE-2014-3635 dbus: heap-based buffer overflow flaw in file descriptor passing
Product: [Other] Security Response Reporter: Murray McAllister <mmcallis>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: jrusnack, rhughes, security-response-team, slawomir.czarko, slawomir, vdanen, walters
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-12-12 23:53:44 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1142581, 1142582, 1142583    
Bug Blocks: 1140534    
Attachments:
Description Flags
initial patch from upstream
none
silence a compiler warning in the previous patch
none
regression test none

Description Murray McAllister 2014-09-11 07:52:03 UTC
A heap-based buffer overflow flaw was reported in D-Bus's file descriptor passing. On 64-bit systems, if the max_message_unix_fds limit was set to an odd number, a local, malicious user could send one more file descriptor than expected. This would cause the dbus-daemon to crash or, potentially, execute arbitrary code.

It is believed that versions 1.3.0 and later are affected.

Acknowledgements:

Red Hat would like to thank D-Bus upstream for reporting this issue. Upstream acknowledges Simon McVittie as the original reporter.

Comment 2 Murray McAllister 2014-09-11 08:28:04 UTC
Created attachment 936433 [details]
initial patch from upstream

Comment 3 Murray McAllister 2014-09-11 08:30:22 UTC
Created attachment 936434 [details]
silence a compiler warning in the previous patch

Comment 4 Murray McAllister 2014-09-11 08:32:18 UTC
Created attachment 936435 [details]
regression test

Comment 5 Murray McAllister 2014-09-17 05:10:44 UTC
Created dbus tracking bugs for this issue:

Affects: fedora-all [bug 1142581]

Comment 6 Murray McAllister 2014-09-17 05:10:47 UTC
Created mingw-dbus tracking bugs for this issue:

Affects: fedora-all [bug 1142582]
Affects: epel-7 [bug 1142583]

Comment 7 Murray McAllister 2014-09-17 05:16:33 UTC
Public now:

http://www.openwall.com/lists/oss-security/2014/09/16/9

Comment 8 Fedora Update System 2014-12-13 09:47:43 UTC
dbus-1.6.28-1.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2014-12-17 04:46:47 UTC
dbus-1.8.12-1.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 10 Fedora Update System 2014-12-19 18:26:31 UTC
dbus-1.6.28-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.