CVE-2014-8156 Details
Description
The D-Bus security policy files in /etc/dbus-1/system.d/*.conf in fso-gsmd 0.12.0-3, fso-frameworkd 0.9.5.9+git20110512-4, and fso-usaged 0.12.0-2 as packaged in Debian, the upstream cornucopia.git (fsoaudiod, fsodatad, fsodeviced, fsogsmd, fsonetworkd, fsotdld, fsousaged) git master on 2015-01-19, the upstream framework.git 0.10.1 and git master on 2015-01-19, phonefsod 0.1+git20121018-1 as packaged in Debian, Ubuntu and potentially other packages, and potentially other fso modules do not properly filter D-Bus message paths, which might allow local users to cause a denial of service (dbus-daemon memory consumption), or execute arbitrary code as root by sending a crafted D-Bus message to any D-Bus system service.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/100488 | CVE | Third Party AdvisoryVDB Entry |
| http://www.openwall.com/lists/oss-security/2015/01/27/25 | CVE | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/72363 | CVE | Third Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/100488 | [email protected] | Third Party AdvisoryVDB Entry |
| http://www.openwall.com/lists/oss-security/2015/01/27/25 | [email protected] | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/72363 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-264 | Permissions, Privileges, and Access Controls | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fso-frameworkd project fso-frameworkd | 0.9.5.9 |
CPE
Remediation
| |
| fso-gsmd project fso-gsmd | 0.12.0-3 |
CPE
Remediation
| |
| fso-usaged project fso-usaged | 0.12.0-2 |
CPE
Remediation
| |
| phonefsod project phonefsod | 0.1 |
CPE
Remediation
| |
| debian debian linux | <= 8.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 11, 2017 | Initial Analysis | [email protected] |
| Sep 29, 2017 | CVE Modified | [email protected] |