Debian Security Advisory DSA-3161-1 [email protected]
http://www.debian.org/security/ Salvatore Bonaccorso
February 11, 2015 http://www.debian.org/security/faq
Package : dbus
CVE ID : CVE-2015-0245
Debian Bug : 777545
Simon McVittie discovered a local denial of service flaw in dbus, an
asynchronous inter-process communication system. On systems with
systemd-style service activation, dbus-daemon does not prevent forged
ActivationFailure messages from non-root processes. A malicious local
user could use this flaw to trick dbus-daemon into thinking that systemd
failed to activate a system service, resulting in an error reply back to
the requester.
For the stable distribution (wheezy), this problem has been fixed in
version 1.6.8-1+deb7u6.
For the unstable distribution (sid), this problem has been fixed in
version 1.8.16-1.
We recommend that you upgrade your dbus packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: [email protected]
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 7 | armhf | dbus-1-dbg | < 1.6.8-1+deb7u6 | dbus-1-dbg_1.6.8-1+deb7u6_armhf.deb |
Debian | 7 | ia64 | dbus-x11 | < 1.6.8-1+deb7u6 | dbus-x11_1.6.8-1+deb7u6_ia64.deb |
Debian | 7 | amd64 | libdbus-1-dev | < 1.6.8-1+deb7u6 | libdbus-1-dev_1.6.8-1+deb7u6_amd64.deb |
Debian | 7 | armel | dbus | < 1.6.8-1+deb7u6 | dbus_1.6.8-1+deb7u6_armel.deb |
Debian | 7 | kfreebsd-amd64 | libdbus-1-3 | < 1.6.8-1+deb7u6 | libdbus-1-3_1.6.8-1+deb7u6_kfreebsd-amd64.deb |
Debian | 7 | s390x | libdbus-1-dev | < 1.6.8-1+deb7u6 | libdbus-1-dev_1.6.8-1+deb7u6_s390x.deb |
Debian | 7 | mips | libdbus-1-dev | < 1.6.8-1+deb7u6 | libdbus-1-dev_1.6.8-1+deb7u6_mips.deb |
Debian | 7 | powerpc | dbus-x11 | < 1.6.8-1+deb7u6 | dbus-x11_1.6.8-1+deb7u6_powerpc.deb |
Debian | 7 | sparc | dbus | < 1.6.8-1+deb7u6 | dbus_1.6.8-1+deb7u6_sparc.deb |
Debian | 7 | mips | libdbus-1-3 | < 1.6.8-1+deb7u6 | libdbus-1-3_1.6.8-1+deb7u6_mips.deb |