Description
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2235-1 | dbus security update |
EUVD |
EUVD-2020-4365 | An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients. |
Ubuntu USN |
USN-4398-1 | DBus vulnerability |
Ubuntu USN |
USN-4398-2 | DBus vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:48:57.950Z
Reserved: 2020-04-21T00:00:00.000Z
Link: CVE-2020-12049
No data.
Status : Modified
Published: 2020-06-08T17:15:09.910
Modified: 2024-11-21T04:59:10.813
Link: CVE-2020-12049
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN