The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection consumption and prevention of new connections) via a large number of incomplete connections.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "dbus", "binary_version": "1.6.18-0ubuntu4.2" }, { "binary_name": "dbus-1-dbg", "binary_version": "1.6.18-0ubuntu4.2" }, { "binary_name": "dbus-1-doc", "binary_version": "1.6.18-0ubuntu4.2" }, { "binary_name": "dbus-x11", "binary_version": "1.6.18-0ubuntu4.2" }, { "binary_name": "libdbus-1-3", "binary_version": "1.6.18-0ubuntu4.2" }, { "binary_name": "libdbus-1-dev", "binary_version": "1.6.18-0ubuntu4.2" } ], "ubuntu_priority": "medium" }