CVE-2011-2200
22.06.2011, 22:55
The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-native byte order, which allows local users to cause a denial of service (connection loss), obtain potentially sensitive information, or conduct unspecified state-modification attacks via crafted messages.Enginsight
| Vendor | Product | Version |
|---|---|---|
| freedesktop | dbus | 1.5.0 |
| freedesktop | dbus | 1.5.2 |
| freedesktop | dbus | 1.4.0 |
| freedesktop | dbus | 1.4.1 |
| freedesktop | dbus | 1.4.4 |
| freedesktop | dbus | 1.4.6 |
| freedesktop | dbus | 1.4.8 |
| freedesktop | dbus | 1.4.10 |
| d-bus_project | d-bus | 1.2.4.2 |
| d-bus_project | d-bus | 1.2.4.4 |
| d-bus_project | d-bus | 1.2.4.6 |
| freedesktop | dbus | 1.2.1 |
| freedesktop | dbus | 1.2.2 |
| freedesktop | dbus | 1.2.3 |
| freedesktop | dbus | 1.2.4 |
| freedesktop | dbus | 1.2.6 |
| freedesktop | dbus | 1.2.8 |
| freedesktop | dbus | 1.2.10 |
| freedesktop | dbus | 1.2.12 |
| freedesktop | dbus | 1.2.14 |
| freedesktop | dbus | 1.2.16 |
| freedesktop | dbus | 1.2.18 |
| freedesktop | dbus | 1.2.20 |
| freedesktop | dbus | 1.2.22 |
| freedesktop | dbus | 1.2.24 |
| freedesktop | dbus | 1.2.26 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References
http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.2&id=6519a1f77c61d753d4c97efd6e15630eb275336e
http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.4&id=c3223ba6c401ba81df1305851312a47c485e6cd7
http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.2&id=6519a1f77c61d753d4c97efd6e15630eb275336e