Lucene search

K
mageiaGentoo FoundationMGASA-2014-0266
HistoryJun 18, 2014 - 11:25 p.m.

Updated dbus packages fix security vulnerability

2014-06-1823:25:42
Gentoo Foundation
advisories.mageia.org
12

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

0.0004 Low

EPSS

Percentile

10.3%

Updated dbus packages fix security vulnerability: A denial of service vulnerability in D-Bus before 1.6.20 allows a local attacker to cause a bus-activated service that is not currently running to attempt to start, and fail, denying other users access to this service Additionally, in highly unusual environments the same flaw could lead to a side channel between processes that should not be able to communicate (CVE-2014-3477).

OSVersionArchitecturePackageVersionFilename
Mageia3noarchdbus< 1.6.8-4.2dbus-1.6.8-4.2.mga3
Mageia4noarchdbus< 1.6.18-1.1dbus-1.6.18-1.1.mga4

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

0.0004 Low

EPSS

Percentile

10.3%