Vulnerability CVE-2023-34969: Information

Description

D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Published: June 8, 2023
Modified: Dec. 27, 2023

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
dbussisyphus1.14.8-alt11.14.10-alt1ALT-PU-2023-4139-1324298Fixed
dbussisyphus_e2k1.14.8-alt11.14.10-alt1ALT-PU-2023-4193-1-Fixed
dbussisyphus_riscv641.14.8-alt11.14.10-alt1ALT-PU-2023-4217-1-Fixed
dbusp101.14.8-alt11.14.10-alt1ALT-PU-2023-4115-2324300Fixed
dbusp10_e2k1.14.8-alt11.14.10-alt1ALT-PU-2023-5089-1-Fixed
dbusc10f11.14.8-alt11.14.8-alt1ALT-PU-2024-3680-2340648Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:*
      Start including
      1.15.0
      End excliding
      1.15.6

      cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:*
      Start including
      1.14.0
      End excliding
      1.14.8

      cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:*
      Start including
      1.12.0
      End excliding
      1.12.28

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*