Vulnerability CVE-2006-6107


Published: 2006-12-13   Modified: 2012-02-12

Description:
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).

CVSS2 => (AV:L/AC:L/Au:S/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
1.7/10
2.9/10
3.1/10
Exploit range
Attack complexity
Authentication
Local
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
D-bus -> D-bus 

 References:
https://bugs.freedesktop.org/show_bug.cgi?id=9142
http://www.securityfocus.com/bid/21571
http://www.vupen.com/english/advisories/2006/4988
http://www.freedesktop.org/wiki/Software/dbus
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9951
http://lists.opensuse.org/opensuse-updates/2012-10/msg00094.html
https://issues.rpath.com/browse/RPL-860
http://xforce.iss.net/xforce/xfdb/30874
http://www.ubuntu.com/usn/usn-401-1
http://www.securitytracker.com/id?1017608
http://www.redhat.com/support/errata/RHSA-2007-0008.html
http://secunia.com/advisories/24131
http://secunia.com/advisories/24059
http://secunia.com/advisories/23611
http://secunia.com/advisories/23390
http://secunia.com/advisories/23373
http://openpkg.com/go/OpenPKG-SA-2006.041
http://lists.rpath.com/pipermail/security-announce/2007-February/000147.html
http://archives.mandrivalinux.com/security-announce/2006-12/msg00025.php

Copyright 2024, cxsecurity.com

 

Back to Top