CVE-2014-7824
Publication date 18 November 2014
Last updated 24 July 2024
Ubuntu priority
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
Status
Package | Ubuntu Release | Status |
---|---|---|
dbus | ||
14.04 LTS trusty |
Fixed 1.6.18-0ubuntu4.3
|
|
Notes
mdeslaur
also should include regression fix for CVE-2014-3639: https://bugs.freedesktop.org/show_bug.cgi?id=86431
References
Related Ubuntu Security Notices (USN)
- USN-2425-1
- DBus vulnerability
- 27 November 2014