CVE-2008-3834

The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.
References
Link Resource
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html
http://lists.opensuse.org/opensuse-updates/2012-10/msg00094.html
http://secunia.com/advisories/32127 Vendor Advisory
http://secunia.com/advisories/32230
http://secunia.com/advisories/32281
http://secunia.com/advisories/32385
http://secunia.com/advisories/33396
http://www.debian.org/security/2008/dsa-1658
http://www.freedesktop.org/wiki/Software/dbus#head-dad0dab297a44f1d7a3b1259cfc06b583fd6a88a
http://www.mandriva.com/security/advisories?name=MDVSA-2008:213
http://www.redhat.com/support/errata/RHSA-2009-0008.html
http://www.securityfocus.com/bid/31602
http://www.securitytracker.com/id?1021063
http://www.ubuntu.com/usn/usn-653-1
http://www.vupen.com/english/advisories/2008/2762
https://bugs.freedesktop.org/show_bug.cgi?id=17803
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-3834
https://exchange.xforce.ibmcloud.com/vulnerabilities/45701
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10253
https://www.exploit-db.com/exploits/7822
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00298.html
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html
http://lists.opensuse.org/opensuse-updates/2012-10/msg00094.html
http://secunia.com/advisories/32127 Vendor Advisory
http://secunia.com/advisories/32230
http://secunia.com/advisories/32281
http://secunia.com/advisories/32385
http://secunia.com/advisories/33396
http://www.debian.org/security/2008/dsa-1658
http://www.freedesktop.org/wiki/Software/dbus#head-dad0dab297a44f1d7a3b1259cfc06b583fd6a88a
http://www.mandriva.com/security/advisories?name=MDVSA-2008:213
http://www.redhat.com/support/errata/RHSA-2009-0008.html
http://www.securityfocus.com/bid/31602
http://www.securitytracker.com/id?1021063
http://www.ubuntu.com/usn/usn-653-1
http://www.vupen.com/english/advisories/2008/2762
https://bugs.freedesktop.org/show_bug.cgi?id=17803
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-3834
https://exchange.xforce.ibmcloud.com/vulnerabilities/45701
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10253
https://www.exploit-db.com/exploits/7822
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00298.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.1:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.2:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.3:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.4:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.5:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.6:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.7:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.8:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.9:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.10:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.11:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.12:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.13:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.20:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.21:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.22:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.23:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.23.1:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.23.2:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.23.3:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.31:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.32:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.33:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.34:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.35:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.35.1:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.35.2:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.36:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.36.1:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.36.2:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.50:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.61:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.62:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.90:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.91:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:0.92:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus1.0:rc1:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus1.0:rc2:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus1.0:rc3:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus1.1.0:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:50

Type Values Removed Values Added
References () http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 - () http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 -
References () http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html - () http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html -
References () http://lists.opensuse.org/opensuse-updates/2012-10/msg00094.html - () http://lists.opensuse.org/opensuse-updates/2012-10/msg00094.html -
References () http://secunia.com/advisories/32127 - Vendor Advisory () http://secunia.com/advisories/32127 - Vendor Advisory
References () http://secunia.com/advisories/32230 - () http://secunia.com/advisories/32230 -
References () http://secunia.com/advisories/32281 - () http://secunia.com/advisories/32281 -
References () http://secunia.com/advisories/32385 - () http://secunia.com/advisories/32385 -
References () http://secunia.com/advisories/33396 - () http://secunia.com/advisories/33396 -
References () http://www.debian.org/security/2008/dsa-1658 - () http://www.debian.org/security/2008/dsa-1658 -
References () http://www.freedesktop.org/wiki/Software/dbus#head-dad0dab297a44f1d7a3b1259cfc06b583fd6a88a - () http://www.freedesktop.org/wiki/Software/dbus#head-dad0dab297a44f1d7a3b1259cfc06b583fd6a88a -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2008:213 - () http://www.mandriva.com/security/advisories?name=MDVSA-2008:213 -
References () http://www.redhat.com/support/errata/RHSA-2009-0008.html - () http://www.redhat.com/support/errata/RHSA-2009-0008.html -
References () http://www.securityfocus.com/bid/31602 - () http://www.securityfocus.com/bid/31602 -
References () http://www.securitytracker.com/id?1021063 - () http://www.securitytracker.com/id?1021063 -
References () http://www.ubuntu.com/usn/usn-653-1 - () http://www.ubuntu.com/usn/usn-653-1 -
References () http://www.vupen.com/english/advisories/2008/2762 - () http://www.vupen.com/english/advisories/2008/2762 -
References () https://bugs.freedesktop.org/show_bug.cgi?id=17803 - () https://bugs.freedesktop.org/show_bug.cgi?id=17803 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-3834 - () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-3834 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/45701 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/45701 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10253 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10253 -
References () https://www.exploit-db.com/exploits/7822 - () https://www.exploit-db.com/exploits/7822 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00298.html - () https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00298.html -

Information

Published : 2008-10-07 21:01

Updated : 2024-11-21 00:50


NVD link : CVE-2008-3834

Mitre link : CVE-2008-3834

CVE.ORG link : CVE-2008-3834


JSON object : View

Products Affected

freedesktop

  • dbus
  • dbus1.0
  • dbus1.1.0
CWE
CWE-20

Improper Input Validation