Impact
The Jahlives openssl_encrypt package includes an optional D‑Bus crypto service in versions 1.4.x. The service’s org.freedesktop.DBus.Properties.Set method fails to perform any polkit authorization or validate values supplied by callers. An attacker who can exploit any local user account on the system bus can call Set and set configuration parameters such as MaxConcurrentOperations or DefaultTimeout to values that either block all future cryptographic operations or remove limits. The result is a persistent denial of service for the root‑daemon that relies on that cryptographic service. This vulnerability is a data‑input validation flaw (CWE‑20) and permits non‑privileged local users to leverage the failure to authorize calls to a service exposed on the local bus.
Affected Systems
The affected vendor is jahlives for the openssl_encrypt package. The vulnerability exists in the 1.4.x line and is fixed in 1.5.x, where the optional D‑Bus service was removed entirely.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. However, because the flaw can be triggered by any local user, it remains a significant risk in environments where the affected package is in use. The attack vector is local, leveraging the system bus, and requires no special privileges beyond access to the D‑Bus session.
OpenCVE Enrichment