CVE-2014-8156
Summary
| CVE | CVE-2014-8156 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-26 01:29:00 UTC |
| Updated | 2017-10-11 19:23:00 UTC |
| Description | The D-Bus security policy files in /etc/dbus-1/system.d/*.conf in fso-gsmd 0.12.0-3, fso-frameworkd 0.9.5.9+git20110512-4, and fso-usaged 0.12.0-2 as packaged in Debian, the upstream cornucopia.git (fsoaudiod, fsodatad, fsodeviced, fsogsmd, fsonetworkd, fsotdld, fsousaged) git master on 2015-01-19, the upstream framework.git 0.10.1 and git master on 2015-01-19, phonefsod 0.1+git20121018-1 as packaged in Debian, Ubuntu and potentially other packages, and potentially other fso modules do not properly filter D-Bus message paths, which might allow local users to cause a denial of service (dbus-daemon memory consumption), or execute arbitrary code as root by sending a crafted D-Bus message to any D-Bus system service. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | All | All | All | All |
| Operating System | Debian | Debian Linux | All | All | All | All |
| Application | Fso-frameworkd Project | Fso-frameworkd | 0.9.5.9 | All | All | All |
| Application | Fso-frameworkd Project | Fso-frameworkd | 0.9.5.9 | All | All | All |
| Application | Fso-gsmd Project | Fso-gsmd | 0.12.0-3 | All | All | All |
| Application | Fso-gsmd Project | Fso-gsmd | 0.12.0-3 | All | All | All |
| Application | Fso-usaged Project | Fso-usaged | 0.12.0-2 | All | All | All |
| Application | Fso-usaged Project | Fso-usaged | 0.12.0-2 | All | All | All |
| Application | Phonefsod Project | Phonefsod | 0.1 | All | All | All |
| Application | Phonefsod Project | Phonefsod | 0.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| freesmartphone.org CVE-2014-8156 Local Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| oss-security - CVE-2014-8156: freesmartphone.org stack configures D-Bus system bus to be insecure | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.