Vulnerability Details CVE-2023-34969
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.0%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2023-34969
-
cpe:2.3:a:freedesktop:dbus:1.12.0
-
cpe:2.3:a:freedesktop:dbus:1.12.10
-
cpe:2.3:a:freedesktop:dbus:1.12.12
-
cpe:2.3:a:freedesktop:dbus:1.12.14
-
cpe:2.3:a:freedesktop:dbus:1.12.16
-
cpe:2.3:a:freedesktop:dbus:1.12.18
-
cpe:2.3:a:freedesktop:dbus:1.12.2
-
cpe:2.3:a:freedesktop:dbus:1.12.20
-
cpe:2.3:a:freedesktop:dbus:1.12.22
-
cpe:2.3:a:freedesktop:dbus:1.12.24
-
cpe:2.3:a:freedesktop:dbus:1.12.26
-
cpe:2.3:a:freedesktop:dbus:1.12.4
-
cpe:2.3:a:freedesktop:dbus:1.12.6
-
cpe:2.3:a:freedesktop:dbus:1.12.8
-
cpe:2.3:a:freedesktop:dbus:1.14.0
-
cpe:2.3:a:freedesktop:dbus:1.14.2
-
cpe:2.3:a:freedesktop:dbus:1.14.4
-
cpe:2.3:a:freedesktop:dbus:1.14.6
-
cpe:2.3:a:freedesktop:dbus:1.15.0
-
cpe:2.3:a:freedesktop:dbus:1.15.2
-
cpe:2.3:a:freedesktop:dbus:1.15.4
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:fedoraproject:fedora:38