Vulnerabilities > CVE-2010-4352 - Resource Management Errors vulnerability in D-Bus Project D-Bus

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
local
low complexity
d-bus-project
CWE-399
nessus

Summary

Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyScientific Linux Local Security Checks
    NASL idSL_20110322_DBUS_ON_SL5_X.NASL
    descriptionA denial of service flaw was discovered in the system for sending messages between applications. A local user could send a message with an excessive number of nested variants to the system-wide message bus, causing the message bus (and, consequently, any process using libdbus to receive messages) to abort. (CVE-2010-4352) For the update to take effect, all running instances of dbus-daemon and all running applications using the libdbus library must be restarted, or the system rebooted.
    last seen2020-06-01
    modified2020-06-02
    plugin id60992
    published2012-08-01
    reporterThis script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/60992
    titleScientific Linux Security Update : dbus on SL5.x, SL6.x i386/x86_64
  • NASL familyCentOS Local Security Checks
    NASL idCENTOS_RHSA-2011-0376.NASL
    descriptionUpdated dbus packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. D-Bus is a system for sending messages between applications. It is used for the system-wide message bus service and as a per-user-login-session messaging facility. A denial of service flaw was discovered in the system for sending messages between applications. A local user could send a message with an excessive number of nested variants to the system-wide message bus, causing the message bus (and, consequently, any process using libdbus to receive messages) to abort. (CVE-2010-4352) All users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. For the update to take effect, all running instances of dbus-daemon and all running applications using the libdbus library must be restarted, or the system rebooted.
    last seen2020-06-01
    modified2020-06-02
    plugin id53429
    published2011-04-15
    reporterThis script is Copyright (C) 2011-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/53429
    titleCentOS 5 : dbus (CESA-2011:0376)
  • NASL familyOracle Linux Local Security Checks
    NASL idORACLELINUX_ELSA-2011-0376.NASL
    descriptionFrom Red Hat Security Advisory 2011:0376 : Updated dbus packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. D-Bus is a system for sending messages between applications. It is used for the system-wide message bus service and as a per-user-login-session messaging facility. A denial of service flaw was discovered in the system for sending messages between applications. A local user could send a message with an excessive number of nested variants to the system-wide message bus, causing the message bus (and, consequently, any process using libdbus to receive messages) to abort. (CVE-2010-4352) All users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. For the update to take effect, all running instances of dbus-daemon and all running applications using the libdbus library must be restarted, or the system rebooted.
    last seen2020-06-01
    modified2020-06-02
    plugin id68236
    published2013-07-12
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/68236
    titleOracle Linux 5 / 6 : dbus (ELSA-2011-0376)
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2011-0376.NASL
    descriptionUpdated dbus packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. D-Bus is a system for sending messages between applications. It is used for the system-wide message bus service and as a per-user-login-session messaging facility. A denial of service flaw was discovered in the system for sending messages between applications. A local user could send a message with an excessive number of nested variants to the system-wide message bus, causing the message bus (and, consequently, any process using libdbus to receive messages) to abort. (CVE-2010-4352) All users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. For the update to take effect, all running instances of dbus-daemon and all running applications using the libdbus library must be restarted, or the system rebooted.
    last seen2020-06-01
    modified2020-06-02
    plugin id52764
    published2011-03-23
    reporterThis script is Copyright (C) 2011-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/52764
    titleRHEL 5 / 6 : dbus (RHSA-2011:0376)
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2011-0439.NASL
    descriptionAn updated rhev-hypervisor package that fixes one security issue and one bug is now available. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. The rhev-hypervisor package provides a Red Hat Enterprise Virtualization Hypervisor ISO disk image. The Red Hat Enterprise Virtualization Hypervisor is a dedicated Kernel-based Virtual Machine (KVM) hypervisor. It includes everything necessary to run and manage virtual machines: A subset of the Red Hat Enterprise Linux operating environment and the Red Hat Enterprise Virtualization Agent. Note: Red Hat Enterprise Virtualization Hypervisor is only available for the Intel 64 and AMD64 architectures with virtualization extensions. A NULL pointer dereference flaw was found in the Generic Receive Offload (GRO) functionality in the Linux kernel
    last seen2020-06-01
    modified2020-06-02
    plugin id79278
    published2014-11-17
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/79278
    titleRHEL 5 : rhev-hypervisor (RHSA-2011:0439)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_3_DBUS-1-110426.NASL
    descriptionLocal users could crash the D-Bus daemon by sending a specially crafted message (CVE-2010-4352).
    last seen2020-06-01
    modified2020-06-02
    plugin id75460
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/75460
    titleopenSUSE Security Update : dbus-1 (openSUSE-SU-2011:0401-1)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_DBUS-1-7482.NASL
    descriptionLocal users could crash the D-Bus daemon by sending a specially crafted message (CVE-2010-4352). This update also properly fixes CVE-2008-3834 / CVE-2009-1189.
    last seen2020-06-01
    modified2020-06-02
    plugin id57177
    published2011-12-13
    reporterThis script is Copyright (C) 2011-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/57177
    titleSuSE 10 Security Update : dbus (ZYPP Patch Number 7482)
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-201110-14.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-201110-14 (D-Bus: Multiple vulnerabilities) Multiple vulnerabilities have been discovered in D-Bus. Please review the CVE identifiers referenced below for details. Impact : The vulnerabilities allow for local Denial of Service (daemon crash), or arbitrary file overwriting. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id56589
    published2011-10-24
    reporterThis script is Copyright (C) 2011-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/56589
    titleGLSA-201110-14 : D-Bus: Multiple vulnerabilities
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-2149.NASL
    descriptionRemi Denis-Courmont discovered that dbus, a message bus application, is not properly limiting the nesting level when examining messages with extensive nested variants. This allows an attacker to crash the dbus system daemon due to a call stack overflow via crafted messages.
    last seen2020-03-17
    modified2011-01-21
    plugin id51588
    published2011-01-21
    reporterThis script is Copyright (C) 2011-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/51588
    titleDebian DSA-2149-1 : dbus - denial of service
  • NASL familyUbuntu Local Security Checks
    NASL idUBUNTU_USN-1044-1.NASL
    descriptionRemi Denis-Courmont discovered that D-Bus did not properly validate the number of nested variants when validating D-Bus messages. A local attacker could exploit this to cause a denial of service. Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id51572
    published2011-01-19
    reporterUbuntu Security Notice (C) 2011-2019 Canonical, Inc. / NASL script (C) 2011-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/51572
    titleUbuntu 8.04 LTS / 9.10 / 10.04 LTS / 10.10 : dbus vulnerability (USN-1044-1)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2010-19166.NASL
    descriptionYou need to reboot to apply this update. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id51378
    published2010-12-26
    reporterThis script is Copyright (C) 2010-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/51378
    titleFedora 14 : dbus-1.4.0-2.fc14 (2010-19166)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2010-19178.NASL
    descriptionYou need to reboot to apply this update. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id53395
    published2011-04-13
    reporterThis script is Copyright (C) 2011-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/53395
    titleFedora 13 : dbus-1.2.24-2.fc13 (2010-19178)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_DBUS-1-110418.NASL
    descriptionLocal users could crash the D-Bus daemon by sending a specially crafted message (CVE-2010-4352). This update also properly fixes CVE-2008-3834 / CVE-2009-1189.
    last seen2020-06-01
    modified2020-06-02
    plugin id53587
    published2011-04-29
    reporterThis script is Copyright (C) 2011-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/53587
    titleSuSE 11.1 Security Update : dbus (SAT Patch Number 4434)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_DBUS-1-7483.NASL
    descriptionLocal users could crash the D-Bus daemon by sending a specially crafted message (CVE-2010-4352). This update also properly fixes CVE-2008-3834 / CVE-2009-1189.
    last seen2020-06-01
    modified2020-06-02
    plugin id53590
    published2011-04-29
    reporterThis script is Copyright (C) 2011-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/53590
    titleSuSE 10 Security Update : dbus (ZYPP Patch Number 7483)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_DBUS-1-110211.NASL
    descriptionLocal users could crash the D-Bus daemon by sending a specially crafted message. (CVE-2010-4352) Also RPM requirements were adjusted to make appliance installations work better.
    last seen2020-06-01
    modified2020-06-02
    plugin id52066
    published2011-02-22
    reporterThis script is Copyright (C) 2011-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/52066
    titleSuSE 11.1 Security Update : dbus (SAT Patch Number 3941)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_2_DBUS-1-110426.NASL
    descriptionLocal users could crash the D-Bus daemon by sending a specially crafted message (CVE-2010-4352).
    last seen2020-06-01
    modified2020-06-02
    plugin id53704
    published2011-05-05
    reporterThis script is Copyright (C) 2011-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/53704
    titleopenSUSE Security Update : dbus-1 (openSUSE-SU-2011:0401-1)
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2012-750.NASL
    description6 vulnerabilities were discovered for the dbus-1 and dbus-1-x11 packages in openSUSE versions 11.4, 12.1, and 12.2.
    last seen2020-06-05
    modified2014-06-13
    plugin id74795
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/74795
    titleopenSUSE Security Update : dbus-1 / dbus-1-x11 (openSUSE-SU-2012:1418-1)

Redhat

advisories
bugzilla
id663673
titleCVE-2010-4352 D-BUS: Stack overflow by validating message with excessive number of nested variants
oval
OR
  • commentRed Hat Enterprise Linux must be installed
    ovaloval:com.redhat.rhba:tst:20070304026
  • AND
    • commentRed Hat Enterprise Linux 6 is installed
      ovaloval:com.redhat.rhba:tst:20111656003
    • OR
      • AND
        • commentdbus-doc is earlier than 1:1.2.24-4.el6_0
          ovaloval:com.redhat.rhsa:tst:20110376001
        • commentdbus-doc is signed with Red Hat redhatrelease2 key
          ovaloval:com.redhat.rhsa:tst:20110376002
      • AND
        • commentdbus-devel is earlier than 1:1.2.24-4.el6_0
          ovaloval:com.redhat.rhsa:tst:20110376003
        • commentdbus-devel is signed with Red Hat redhatrelease2 key
          ovaloval:com.redhat.rhsa:tst:20110376004
      • AND
        • commentdbus-libs is earlier than 1:1.2.24-4.el6_0
          ovaloval:com.redhat.rhsa:tst:20110376005
        • commentdbus-libs is signed with Red Hat redhatrelease2 key
          ovaloval:com.redhat.rhsa:tst:20110376006
      • AND
        • commentdbus is earlier than 1:1.2.24-4.el6_0
          ovaloval:com.redhat.rhsa:tst:20110376007
        • commentdbus is signed with Red Hat redhatrelease2 key
          ovaloval:com.redhat.rhsa:tst:20110376008
      • AND
        • commentdbus-x11 is earlier than 1:1.2.24-4.el6_0
          ovaloval:com.redhat.rhsa:tst:20110376009
        • commentdbus-x11 is signed with Red Hat redhatrelease2 key
          ovaloval:com.redhat.rhsa:tst:20110376010
  • AND
    • commentRed Hat Enterprise Linux 5 is installed
      ovaloval:com.redhat.rhba:tst:20070331005
    • OR
      • AND
        • commentdbus-libs is earlier than 0:1.1.2-15.el5_6
          ovaloval:com.redhat.rhsa:tst:20110376012
        • commentdbus-libs is signed with Red Hat redhatrelease key
          ovaloval:com.redhat.rhsa:tst:20100018002
      • AND
        • commentdbus is earlier than 0:1.1.2-15.el5_6
          ovaloval:com.redhat.rhsa:tst:20110376014
        • commentdbus is signed with Red Hat redhatrelease key
          ovaloval:com.redhat.rhsa:tst:20080159002
      • AND
        • commentdbus-x11 is earlier than 0:1.1.2-15.el5_6
          ovaloval:com.redhat.rhsa:tst:20110376016
        • commentdbus-x11 is signed with Red Hat redhatrelease key
          ovaloval:com.redhat.rhsa:tst:20080159004
      • AND
        • commentdbus-devel is earlier than 0:1.1.2-15.el5_6
          ovaloval:com.redhat.rhsa:tst:20110376018
        • commentdbus-devel is signed with Red Hat redhatrelease key
          ovaloval:com.redhat.rhsa:tst:20080159006
rhsa
idRHSA-2011:0376
released2011-03-22
severityModerate
titleRHSA-2011:0376: dbus security update (Moderate)
rpms
  • dbus-0:1.1.2-15.el5_6
  • dbus-1:1.2.24-4.el6_0
  • dbus-debuginfo-0:1.1.2-15.el5_6
  • dbus-debuginfo-1:1.2.24-4.el6_0
  • dbus-devel-0:1.1.2-15.el5_6
  • dbus-devel-1:1.2.24-4.el6_0
  • dbus-doc-1:1.2.24-4.el6_0
  • dbus-libs-0:1.1.2-15.el5_6
  • dbus-libs-1:1.2.24-4.el6_0
  • dbus-x11-0:1.1.2-15.el5_6
  • dbus-x11-1:1.2.24-4.el6_0