D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections for processes that have terminated, which allows local users to cause a denial of service via a D-bus message containing a D-Bus connection file descriptor.
{
"binaries": [
{
"binary_version": "1.6.18-0ubuntu4.2",
"binary_name": "dbus"
},
{
"binary_version": "1.6.18-0ubuntu4.2",
"binary_name": "dbus-x11"
},
{
"binary_version": "1.6.18-0ubuntu4.2",
"binary_name": "libdbus-1-3"
},
{
"binary_version": "1.6.18-0ubuntu4.2",
"binary_name": "libdbus-1-dev"
}
],
"availability": "No subscription required"
}