Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-12049

Опубликовано: 04 июн. 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.

An uncontrolled resource consumption vulnerability was discovered in D-Bus. The DBusServer leaks file descriptors when a message exceeds the per-message file descriptor limit. This flaw allows a local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket, to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients. As a result, the system may become unusable for other users, and some services may stop working. The highest threat from this vulnerability is to system availability.

Отчет

This issue did not affect the versions of dbus as shipped with Red Hat Enterprise Linux 5, and 6 as they did not include the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dbusNot affected
Red Hat Enterprise Linux 6dbusNot affected
Red Hat Enterprise Linux 7dbusFixedRHSA-2020:289413.07.2020
Red Hat Enterprise Linux 8dbusFixedRHSA-2020:301421.07.2020
Red Hat Enterprise Linux 8dbusFixedRHSA-2020:301421.07.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsdbusFixedRHSA-2020:304421.07.2020
Red Hat Enterprise Linux 8.1 Extended Update SupportdbusFixedRHSA-2020:329804.08.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1849041dbus: denial of service via file descriptor leak

EPSS

Процентиль: 26%
0.00093
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.

CVSS3: 5.5
nvd
больше 5 лет назад

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.

CVSS3: 5.5
debian
больше 5 лет назад

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServe ...

suse-cvrf
больше 4 лет назад

Security update for dbus-1

suse-cvrf
больше 4 лет назад

Security update for dbus-1

EPSS

Процентиль: 26%
0.00093
Низкий

6.5 Medium

CVSS3