// For flags

CVE-2008-3834

D-Bus Daemon < 1.2.4 - 'libdbus' Denial of Service

Severity Score

10.0
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.

La función dbus_signature_validat en la librería D-bus (libdbus), versiones anteriores a 1.2.4, permite a los atacantes remotos causar una denegación de servicios (aplicación suspendida) a través de un mensaje que contiene una firma mal formada, el cual lanza un error assertion.

Havoc Pennington discovered that the D-Bus daemon did not correctly validate certain security policies. If a local user sent a specially crafted D-Bus request, they could bypass security policies that had a "send_interface" defined. It was discovered that the D-Bus library did not correctly validate certain corrupted signatures. If a local user sent a specially crafted D-Bus request, they could crash applications linked against the D-Bus library, leading to a denial of service.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-08-27 CVE Reserved
  • 2008-10-07 CVE Published
  • 2009-01-20 First Exploit
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-20: Improper Input Validation
CAPEC
References (25)
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
<= 1.1.4
Search vendor "Freedesktop" for product "Dbus" and version " <= 1.1.4"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.1
Search vendor "Freedesktop" for product "Dbus" and version "0.1"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.2
Search vendor "Freedesktop" for product "Dbus" and version "0.2"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.3
Search vendor "Freedesktop" for product "Dbus" and version "0.3"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.4
Search vendor "Freedesktop" for product "Dbus" and version "0.4"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.5
Search vendor "Freedesktop" for product "Dbus" and version "0.5"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.6
Search vendor "Freedesktop" for product "Dbus" and version "0.6"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.7
Search vendor "Freedesktop" for product "Dbus" and version "0.7"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.8
Search vendor "Freedesktop" for product "Dbus" and version "0.8"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.9
Search vendor "Freedesktop" for product "Dbus" and version "0.9"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.10
Search vendor "Freedesktop" for product "Dbus" and version "0.10"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.11
Search vendor "Freedesktop" for product "Dbus" and version "0.11"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.12
Search vendor "Freedesktop" for product "Dbus" and version "0.12"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.13
Search vendor "Freedesktop" for product "Dbus" and version "0.13"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.20
Search vendor "Freedesktop" for product "Dbus" and version "0.20"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.21
Search vendor "Freedesktop" for product "Dbus" and version "0.21"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.22
Search vendor "Freedesktop" for product "Dbus" and version "0.22"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.23
Search vendor "Freedesktop" for product "Dbus" and version "0.23"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.23.1
Search vendor "Freedesktop" for product "Dbus" and version "0.23.1"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.23.2
Search vendor "Freedesktop" for product "Dbus" and version "0.23.2"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.23.3
Search vendor "Freedesktop" for product "Dbus" and version "0.23.3"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.31
Search vendor "Freedesktop" for product "Dbus" and version "0.31"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.32
Search vendor "Freedesktop" for product "Dbus" and version "0.32"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.33
Search vendor "Freedesktop" for product "Dbus" and version "0.33"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.34
Search vendor "Freedesktop" for product "Dbus" and version "0.34"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.35
Search vendor "Freedesktop" for product "Dbus" and version "0.35"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.35.1
Search vendor "Freedesktop" for product "Dbus" and version "0.35.1"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.35.2
Search vendor "Freedesktop" for product "Dbus" and version "0.35.2"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.36
Search vendor "Freedesktop" for product "Dbus" and version "0.36"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.36.1
Search vendor "Freedesktop" for product "Dbus" and version "0.36.1"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.36.2
Search vendor "Freedesktop" for product "Dbus" and version "0.36.2"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.50
Search vendor "Freedesktop" for product "Dbus" and version "0.50"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.61
Search vendor "Freedesktop" for product "Dbus" and version "0.61"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.62
Search vendor "Freedesktop" for product "Dbus" and version "0.62"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.90
Search vendor "Freedesktop" for product "Dbus" and version "0.90"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.91
Search vendor "Freedesktop" for product "Dbus" and version "0.91"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
0.92
Search vendor "Freedesktop" for product "Dbus" and version "0.92"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
1.0.2
Search vendor "Freedesktop" for product "Dbus" and version "1.0.2"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
1.1.1
Search vendor "Freedesktop" for product "Dbus" and version "1.1.1"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
1.1.2
Search vendor "Freedesktop" for product "Dbus" and version "1.1.2"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus1.0
Search vendor "Freedesktop" for product "Dbus1.0"
rc1
Search vendor "Freedesktop" for product "Dbus1.0" and version "rc1"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus1.0
Search vendor "Freedesktop" for product "Dbus1.0"
rc2
Search vendor "Freedesktop" for product "Dbus1.0" and version "rc2"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus1.0
Search vendor "Freedesktop" for product "Dbus1.0"
rc3
Search vendor "Freedesktop" for product "Dbus1.0" and version "rc3"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus1.1.0
Search vendor "Freedesktop" for product "Dbus1.1.0"
*-
Affected