Vulnerability identifier: #VU67528
Vulnerability risk: Low
CVSSv3.1:
CVE-ID:
CWE-ID:
CWE-476
Exploitation vector: Local
Exploit availability: Yes
Vulnerable software:
Linux D-Bus Message Broker
Universal components / Libraries /
Libraries used by multiple products
Vendor: bus1
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error when handling a malformed XML config file. A local user can supply a specially crafted XML file to the service and perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux D-Bus Message Broker: 1 - 30
CPE
External links
http://sec-consult.com/vulnerability-lab/advisory/memory-corruption-vulnerabilities-dbus-broker/
http://github.com/bus1/dbus-broker/compare/v30...v31
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?