CVE-2020-12049 - log back

CVE-2020-12049 edited at 09 Jun 2020 08:12:19
Severity
- Unknown
+ Low
Remote
- Unknown
+ Local
Type
- Unknown
+ Denial of service
Description
+ An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.
References
+ https://www.openwall.com/lists/oss-security/2020/06/04/3
+ https://gitlab.freedesktop.org/dbus/dbus/-/issues/294
+ https://gitlab.freedesktop.org/dbus/dbus/-/commit/872b085f12f56da25a2dbd9bd0b2dff31d5aea63
Notes
CVE-2020-12049 created at 09 Jun 2020 08:09:09