>> D-Bus Signature Validation Local Denial of Service Vulnerability
Title : D-Bus Signature Validation Local Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-2762 CVE ID : CVE-2008-3834 - CVE-2009-1189
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-10-08
Technical Description
A vulnerability has been identified in D-Bus, which could be exploited by local attackers to cause a denial of service. This issue is caused by a design error in the "_dbus_validate_signature_with_reason()" [dbus/dbus-marshal-validate.c] function when validating malformed signatures, which could be exploited by malicious users to cause a vulnerable application to abort, creating a denial of service condition.