• [SECURITY] [DSA 2971-1] dbus security update

    From Salvatore Bonaccorso@1:229/2 to All on Wed Jul 2 20:50:01 2014
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2971-1 [email protected] http://www.debian.org/security/ Salvatore Bonaccorso
    July 02, 2014 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : dbus
    CVE ID : CVE-2014-3477 CVE-2014-3532 CVE-2014-3533

    Several vulnerabilities have been discovered in dbus, an asynchronous inter-process communication system. The Common Vulnerabilities and
    Exposures project identifies the following problems:

    CVE-2014-3477

    Alban Crequy at Collabora Ltd. discovered that dbus-daemon sends an
    AccessDenied error to the service instead of a client when the
    client is prohibited from accessing the service. A local attacker
    could use this flaw to cause a bus-activated service that is not
    currently running to attempt to start, and fail, denying other users
    access to this service.

    CVE-2014-3532

    Alban Crequy at Collabora Ltd. discovered a bug in dbus-daemon's
    support for file descriptor passing. A malicious process could force
    system services or user applications to be disconnected from the
    D-Bus system by sending them a message containing a file descriptor,
    leading to a denial of service.

    CVE-2014-3533

    Alban Crequy at Collabora Ltd. and Alejandro Martinez Suarez
    discovered that a malicious process could force services to be
    disconnected from the D-Bus system by causing dbus-daemon to attempt
    to forward invalid file descriptors to a victim process, leading to
    a denial of service.

    For the stable distribution (wheezy), these problems have been fixed in
    version 1.6.8-1+deb7u3.

    For the unstable distribution (sid), these problems have been fixed in
    version 1.8.6-1.

    We recommend that you upgrade your dbus packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQIcBAEBCgAGBQJTtE2UAAoJEAVMuPMTQ89EH/QQAJlApEGPFhqUnkoH12Qwpluy f0tzw9luGd6GbXVm3IR8pBOjZgtC2ZGBUlmE1yN0qvcuuhOM0RTf3VICJ4vStyKp 2xUlmjv32y8G0KCBs0ckk0kNDApa7TNufbuuBa1EFI3BIe6V0TnEyr9oXaKicvuV PCUlaM81h13zDw1x2KfHsMWlJyr8uoM6PLlgicdRvtEJ88URBC9ZIieYXdK8rpsY rBiuE9575AxEPtAXV0FUSF371zKXg+ZR3zV4EocrI9liMPigIwrIoqhCTWXfJ0WH 0iLlhG41SLDNiBG/Hw0vlw8kX9/X+dlHQTRYV+qzSYfiBu4wfk/KRaAR0nPdmt+H ik28WCE5B7zyc7KImAgiruYIl9nfiVcJlJVCPav48x8Cij0+zf3tzYdI3Lo4jQTH /cSCXWs47U0Lsj0xMc8vrhRJq2NDybTJiAzeY929snNR5EBfBwmm9GoZfOlfkIPx yPn/TTX3u8N3SFcys0w9zHpL1lrdqZ8pJGTqErA+WlzcFLKMjGArpY1PxdJD8mAE DLkHWz7yY48WfkaDxfc0iscVqKUPzHsPPVedY31wDCKQjJR36lIkTmyOzKyBoKa1 AyYNQVTKGoxkRsxL/riD57/MprpTqFFHAtDGTw1o3ORZpXbqHnLY5A0QaZPCs3M9 l6ellinwf6MDWjEZ7CPj
    =gIUw
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: https://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)