CVE-2008-3834

D-bus <1.2.4 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-3834. PoCs published by Jon Oberheide.

AI-analyzed exploit summary This exploit triggers a denial of service in D-Bus daemon versions prior to 1.2.4 by sending a malformed signature in a message, causing an assertion failure. It constructs a malicious D-Bus message and sends it to both system and session daemons.

Description

The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jon Oberheide · cdosmultiple
https://www.exploit-db.com/exploits/7822

This exploit triggers a denial of service in D-Bus daemon versions prior to 1.2.4 by sending a malformed signature in a message, causing an assertion failure. It constructs a malicious D-Bus message and sends it to both system and session daemons.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: D-Bus (libdbus) < 1.2.4
No auth needed
Prerequisites: D-Bus library development headers · Access to D-Bus system or session daemon
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (22)

Core 22
Core References
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:213
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1658
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31602
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2012-10/msg00094.html
Various Sources x_refsource_confirm
https://bugs.freedesktop.org/show_bug.cgi?id=17803
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021063
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45701
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7822
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32385
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32281
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32230
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10253
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2762
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33396
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32127
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0008.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-653-1

Scores

EPSS 0.0462
EPSS Percentile 90.5%

Details

CWE
CWE-20
Status published
Products (44)
freedesktop/dbus 0.1
freedesktop/dbus 0.2
freedesktop/dbus 0.3
freedesktop/dbus 0.4
freedesktop/dbus 0.5
freedesktop/dbus 0.6
freedesktop/dbus 0.7
freedesktop/dbus 0.8
freedesktop/dbus 0.9
freedesktop/dbus 0.10
... and 34 more
Published Oct 07, 2008
Tracked Since Feb 18, 2026