Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in DBus
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in DBus
ID: USN-1176-1
Distribution: Ubuntu
Plattformen: Ubuntu 8.04 LTS, Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04
Datum: Mi, 27. Juli 2011, 12:42
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2200
Applikationen: D-BUS

Originalnachricht


--===============8145314587170079387==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-ToFoMPnGBbbTwPfeQAly"


--=-ToFoMPnGBbbTwPfeQAly
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1176-1
July 26, 2011

dbus vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

DBus could be made to crash if it processed a specially crafted message.

Software Description:
- dbus: simple interprocess messaging system

Details:

It was discovered that DBus did not properly validate the byte order of
messages under certain circumstances. An attacker could exploit this to
cause a denial of service via application crash or potentially obtain
access to sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
dbus 1.4.6-1ubuntu6.1

Ubuntu 10.10:
dbus 1.4.0-0ubuntu1.3

Ubuntu 10.04 LTS:
dbus 1.2.16-2ubuntu4.3

Ubuntu 8.04 LTS:
dbus 1.1.20-1ubuntu3.5

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1176-1
CVE-2011-2200

Package Information:
https://launchpad.net/ubuntu/+source/dbus/1.4.6-1ubuntu6.1
https://launchpad.net/ubuntu/+source/dbus/1.4.0-0ubuntu1.3
https://launchpad.net/ubuntu/+source/dbus/1.2.16-2ubuntu4.3
https://launchpad.net/ubuntu/+source/dbus/1.1.20-1ubuntu3.5



--ÝoFoMPnGBbbTwPfeQAly
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJOL0bJAAoJEFHb3FjMVZVzdrwP/RblnQf8dTiIdqc6JyqvpC6K
G2ncxkktfySFJha42KTJvdU6GQR0GWCCJoyePQFQ6GE/ninppAIm0j1khL0B7NSi
8hm7ipmMrkiaaz4Tc9Dfx6xF/Uy6NEwaskwEJuKTnDNs22VxhOKD9wX1dKCPPibV
NDFdZdNvUiwK5/gIoHkK0xSnele3RFiZsbuesOOdkES+H8WYGi0r3CNYjaL0NjFE
jkqtfBaABLNOGCd477oy9rZE/tg/YmizayZeTCTyASDDLTSKX4KNsiTc23Ylv2t8
3DdruEKIK57WTDHHOReYcboEUFOK9sqCtG7izwdW5+6z8rZg9chZFeX7zQsGOVC+
c066/hI34993yh8Ubso0kglPrRM++krIsMAqu0s2Ig4VA/0WO1mz0hAztKx8SNQJ
GkoowZ2afr3PoCQ2yjVj8Mt0RvIjTy0ClyLKI2aE3Ck60DGEFb4CBWge8cCMWP+/
Z46TXuA9vAXvydmjYdi7cIYeUKFoXAuwHiGbYCUA+BQe84N+VcunZzTyTtzEw4N+
wGHw9pSFQQI+Bd6oXnz6cICl4ImfkKg1YrKih7b9sa5V50zO5KlxYXo2iY1YZriR
oazOeZQPx4QoQ/xlyCbhrF2+hPSFysBT7BowWZySdrD683XSIZBI5nA4Hk4LWk+T
7R3yGGKeuGMoLXD9LLyA
=Yi1x
-----END PGP SIGNATURE-----

--=-ToFoMPnGBbbTwPfeQAly--



--===============8145314587170079387==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============8145314587170079387==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung