CVE-2014-3477: D-Bus Project D-Bus

Medium severity, CVSS 4.0. EPSS: 0.4% chance of exploitation in the next 30 days.

The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D-Bus message to an inactive service.

Affected products

  • D-Bus Project D-Bus: version 1.2.4.2 only; version 1.2.4.4 only; version 1.2.4.6 only
  • Freedesktop Dbus: version 1.2.1 only; version 1.2.3 only; version 1.2.4 only; version 1.2.6 only; version 1.2.8 only; version 1.2.10 only; …

Published 2014-07-01. Last modified 2026-06-17.