CVE-2015-0245 PUBLISHED

D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before systemd responds.

EPSS 0.09% · 25.8th percentile

Risk Scores

EPSS Score
0.09%
25.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSdbus0, 1.6.12-0ubuntu10, 1.6.18-0ubuntu1

Timeline

References

Open in Interactive Console →