drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in DBus-GLib
Name: |
Ausführen beliebiger Kommandos in DBus-GLib |
|
ID: |
USN-1138-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 8.04 LTS, Ubuntu 10.04 LTS |
|
Datum: |
Fr, 27. Mai 2011, 05:31 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1172 |
|
Applikationen: |
DBus-GLib |
|
Originalnachricht |
--===============1221471019868007517== Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-1yeGM3BGry9gE7ZB7shJ"
--=-1yeGM3BGry9gE7ZB7shJ Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-1138-1 May 26, 2011
dbus-glib vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS - Ubuntu 8.04 LTS
Summary:
An attacker could send crafted input to applications using DBus-GLib and cause them to crash.
Software Description: - dbus-glib: GLib bindings for DBus
Details:
It was discovered that DBus-GLib did not properly verify the access flag of exported GObject properties under certain circumstances. A local attacker could exploit this to bypass intended access restrictions or possibly cause a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 10.04 LTS: libdbus-glib-1-2 0.84-1ubuntu0.2
Ubuntu 8.04 LTS: libdbus-glib-1-2 0.74-2ubuntu0.1
In general, a standard system update will make all the necessary changes.
References: CVE-2010-1172
Package Information: https://launchpad.net/ubuntu/+source/dbus-glib/0.84-1ubuntu0.2 https://launchpad.net/ubuntu/+source/dbus-glib/0.74-2ubuntu0.1
--ÑyeGM3BGry9gE7ZB7shJ Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux)
iQIcBAABCgAGBQJN3szqAAoJEFHb3FjMVZVz7dEP/Rh4QpwgumeYTQYzEafiNQDU zmxtCeR7Bx6h8ulH/C5WUmlKSjdX6OYUVAWDU0l7XUZTEZIk49OjRV/w9tKY/KoA qbwXxgFDL5qBR7vgLRw4ydoAucfxKIgWgNTrl9Se6sd8fvTDXCvi+8Jo2Q1C7Mcy GPmQoGxoStn9x2/aCFVYdut8lO2r+X0G0D9nL9DhEclMXHrdeNCBvbdTFjsz63kx Cbs7cNVjUtMZW95i/Fa7WCoENpOt1Xz8UBc4om/482aZYacZcMjckAl7NVUwg9F8 egeOy+eHsME/cMn3VvwLSGtSIDSF+hsX9aF3Myx+003Lbs0I9N++TlD/2/08DrbL tWj6Gjn0ZYHIyd+XcqZvwqfgbW+V35hcdVdRLpQSaKccRUrPB9Gj2I3sM0BDtalu Mh7eJovu3e94gtpx7H6HuTPZXlgAP/0gnBmGxsAm6R1XITYsm4YBelyHkUw73bq7 iqm7KhLIT0Z158ZCIpS0tJPuz0C35qiWQ1E5hnaBluRLLGn1J3mOr1wfDIKpGjHL AsODrSjHsPGbqjxaAmSyhxvJnuH3LQvC26CKMT5wo2MWG5NGD3UwCi7ugJqP/wKI D5pNZJ1lJk9Gt2FMw8qTZYFGhi9WeB5l3ayQ8Vfh7s/X56kwyNkbGMPua/byLFED MSTPDzx3faPVrDUwAd2K =L2Sb -----END PGP SIGNATURE-----
--=-1yeGM3BGry9gE7ZB7shJ--
--===============1221471019868007517== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============1221471019868007517==--
|
|
|
|