Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1599-1] New dbus packages fix privilege escalation (1/2

    From Moritz Muehlenhoff@1:229/2 to All on Thu Jun 26 23:40:11 2008
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1599-1 [email protected] http://www.debian.org/security/ Moritz Muehlenhoff
    June 26, 2008 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : dbus
    Vulnerability : programming error
    Problem type : local
    Debian-specific: no
    CVE Id(s) : CVE-2008-0595

    Havoc Pennington discovered that DBus, a simple interprocess messaging
    system, performs insufficient validation of security policies, which
    might allow local privilege escalation.

    For the stable distribution (etch), this problem has been fixed in
    version 1.0.2-1+etch1.

    For the unstable distribution (sid), this problem has been fixed in
    version 1.1.20-1.

    We recommend that you upgrade your dbus packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Stable updates are available for alpha, amd64, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

    Source archives:

    http://security.debian.org/pool/updates/main/d/dbus/dbus_1.0.2.orig.tar.gz
    Size/MD5 checksum: 1400278 0552a9b54beb4a044951b7cdbc8fc855
    http://security.debian.org/pool/updates/main/d/dbus/dbus_1.0.2-1+etch1.dsc
    Size/MD5 checksum: 816 17ae5277bdf58c57ae3cf0d313c7c24d
    http://security.debian.org/pool/updates/main/d/dbus/dbus_1.0.2-1+etch1.diff.gz
    Size/MD5 checksum: 19612 a2b0de5bea28219d5e287f6074d7e705

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/d/dbus/dbus-1-doc_1.0.2-1+etch1_all.deb
    Size/MD5 checksum: 1538936 73d480306098e6b0f24062021706ace9

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/d/dbus/dbus-1-utils_1.0.2-1+etch1_alpha.deb
    Size/MD5 checksum: 184618 def6ceaebc79f683ce76cf53fa167466
    http://security.debian.org/pool/updates/main/d/dbus/libdbus-1-dev_1.0.2-1+etch1_alpha.deb
    Size/MD5 checksum: 403498 436cd3405371283d763039834ad091bf
    http://security.debian.org/pool/updates/main/d/dbus/libdbus-1-3_1.0.2-1+etch1_alpha.deb
    Size/MD5 checksum: 288940 f545a2666a651cd883973f3ca0011879
    http://security.debian.org/pool/updates/main/d/dbus/dbus_1.0.2-1+etch1_alpha.deb
    Size/MD5 checksum: 378018 f6f7ea92aa2e5067f6187f57340d9f72

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/d/dbus/dbus-1-utils_1.0.2-1+etch1_amd64.deb
    Size/MD5 checksum: 183978 3ceb93633944d3af0b00d6f08923bd6c
    http://security.debian.org/pool/updates/main/d/dbus/dbus_1.0.2-1+etch1_amd64.deb
    Size/MD5 checksum: 363680 2e392e0cfab4a5cbbb75b5050a3cdf43
    http://security.debian.org/pool/updates/main/d/dbus/libdbus-1-dev_1.0.2-1+etch1_amd64.deb
    Size/MD5 checksum: 348386 e066dc182c9c7f8c31d38979e2400aa1
    http://security.debian.org/pool/updates/main/d/dbus/libdbus-1-3_1.0.2-1+etch1_amd64.deb
    Size/MD5 checksum: 279076 1a133aa27937830c0e57a64f973e9a92

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/d/dbus/dbus_1.0.2-1+etch1_hppa.deb
    Size/MD5 checksum: 375478 fab65297fd67a6be39d41165122a1d27
    http://security.debian.org/pool/updates/main/d/dbus/dbus-1-utils_1.0.2-1+etch1_hppa.deb
    Size/MD5 checksum: 184754 ee3497695d7a9f052cae7dd720930d34
    http://security.debian.org/pool/updates/main/d/dbus/libdbus-1-dev_1.0.2-1+etch1_hppa.deb
    Size/MD5 checksum: 362190 3901ed06fc5bd028eb0164c08d1043d6
    http://security.debian.org/pool/updates/main/d/dbus/libdbus-1-3_1.0.2-1+etch1_hppa.deb
    Size/MD5 checksum: 285788 6b2768ccdd5af272d54f8ea3475a5a69

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/d/dbus/dbus_1.0.2-1+etch1_i386.deb
    Size/MD5 checksum: 350980 062e8d4f7e6091b566723a452e2bfb56
    http://security.debian.org/pool/updates/main/d/dbus/libdbus-1-dev_1.0.2-1+etch1_i386.deb
    Size/MD5 checksum: 335250 88c0dc6fae7b4d92adace225cb546765
    http://security.debian.org/pool/updates/main/d/dbus/dbus-1-utils_1.0.2-1+etch1_i386.deb
    Size/MD5 checksum: 183832 69141c3e3342ea9cc37282fe900ea8e3
    http://security.debian.org/pool/updates/main/d/dbus/libdbus-1-3_1.0.2-1+etch1_i386.deb
    Size/MD5 checksum: 268574 cc3063325ff8c52cf2b2b70ede8c0934

    ia64 architecture (Intel ia64)

    http://security.debian.org/pool/updates/main/d/dbus/dbus-1-utils_1.0.2-1+etch1_ia64.deb
    Size/MD5 checksum: 186470 a922e423c66858c8521cdfb74265b920
    http://security.debian.org/pool/updates/main/d/dbus/dbus_1.0.2-1+etch1_ia64.deb
    Size/MD5 checksum: 439204 7c03f136224406f9cdfb533d019b180b
    http://security.debian.org/pool/updates/main/d/dbus/libdbus-1-dev_1.0.2-1+etch1_ia64.deb
    Size/MD5 checksum: 411344 0928e80a8620c2d16d3dd91e5996d0c3
    http://security.debian.org/pool/updates/main/d/dbus/libdbus-1-3_1.0.2-1+etch1_ia64.deb
    Size/MD5 checksum: 322306 34d62722c2afc0401c7dc5ed884e9abc

    mips architecture (MIPS (Big Endian))

    http://security.debian.org/pool/updates/main/d/dbus/libdbus-1-dev_1.0.2-1+etch1_mips.deb
    Size/MD5 checksum: 359320 543131dff9529461109bb6d31b2ff12f
    http://security.debian.org/pool/updates/main/d/dbus/dbus-1-utils_1.0.2-1+etch1_mips.deb
    Size/MD5 checksum: 183742 671c6a9b380cdfa2f6cb2d19366ec6a3
    http://security.debian.org/pool/updates/main/d/dbus/libdbus-1-3_1.0.2-1+etch1_mips.deb
    Size/MD5 checksum: 272146 cb19335f9af9d39184cb1b8378ef0c1c
    http://security.debian.org/pool/updates/main/d/dbus/dbus_1.0.2-1+etch1_mips.deb
    Size/MD5 checksum: 370474 6d15f43916177eb1f7b2ffe46de2770e

    mipsel architecture (MIPS (Little Endian))


    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Krenn
      Sun Jun 7 01:30:12 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Sat Jun 6 23:27:30 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Sat Jun 6 15:42:53 2026
      from Sheboygan, Wi via Telnet
    • Centurion
      Sat Jun 6 15:32:28 2026
      from Berea, Ohio via Telnet
    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Fri Jun 5 17:52:51 2026
      from Sheboygan, Wi via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 157:00:01
    Calls: 12,093
    Calls today: 1
    Files: 15,000
    Messages: 6,517,746

© >>> Magnum BBS <<<, 2026