Login
Newsletter
Werbung

Sicherheit: Denial of Service in DBus (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Denial of Service in DBus (Aktualisierung)
ID: USN-4398-2
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 ESM, Ubuntu 14.04 ESM
Datum: Mi, 17. Juni 2020, 08:59
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12049
Applikationen: D-BUS
Update von: Denial of Service in DBus

Originalnachricht


--===============7666180128674610653==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="YiEDa0DAkWCtVeE4"
Content-Disposition: inline


--YiEDa0DAkWCtVeE4
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4398-2
June 16, 2020

dbus vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 ESM
- Ubuntu 12.04 ESM

Summary:

DBus could be made to crash if it received specially crafted input.

Software Description:
- dbus: simple interprocess messaging system

Details:

USN-4398-1 fixed a vulnerability in DBus. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.

Original advisory details:

Kevin Backhouse discovered that DBus incorrectly handled file descriptors.
A local attacker could possibly use this issue to cause DBus to crash,
resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
libdbus-1-3 1.6.18-0ubuntu4.5+esm2

Ubuntu 12.04 ESM:
libdbus-1-3 1.4.18-1ubuntu1.10

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
https://usn.ubuntu.com/4398-2
https://usn.ubuntu.com/4398-1
CVE-2020-12049

--YiEDa0DAkWCtVeE4
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAl7pHmgACgkQRbznW4QL
H2nH0A/+PsGM6HaZkkVyXRswBdSt63CF4q0rBc+5y7yolveNE47G+odMhq8X1itB
Ll3/xJv2zbUAB2JRc0FAgS7T22jnHbJ4OKOnkRojONAsNWKvfTrY6or3hhzw+42K
XeONPoflKrmHauTP2D1iKEZ18gxrFJqNlGjhqui7BSF0TqjmPcMGH6DrzyWgvca4
cSJ3lxCJ6hFViL12OjELusksfdVHRR2xzMfEphHq3r/VDlsaDp3ojzj/AoYU2IC5
kzjalmglhRFoISAXakPKT0XnXOBAFzY7GXAWbEMQJt+WZNCSvOk9yLC4dvtHz/49
X+UMnMDj+8Dic1ENBd4cJLuz1B6O7Ywpcsh/tocVS++UnICu2Uoi2Uzm+onM8YvK
8WvMaIOgnNzgqpFvhvPEGPXMjnmArTHsjbdqaVLwkupUxZ5mIqbMJeJI+Rj4uVLo
n6VBuoZAejhqK2gcCl/tNQsSPUUoLZmsJsNJTUkq1CPtOL7+/15DcSIDhqQfo607
hBYVdgZzbsxcQjLUIxK2SHGRTR7FSjRNVRY53jzsx5QoxepQCd5X+W1Q3KDsu20A
Ss7XkAKZpP1fb9R4ruz6Ner829oMIoHPyZbKQcld3s2LsGMF6SVEDfYlpT+Oj8y4
lrRszRBsZ+EtObD79cc/Lfgu6Qf6LUF0Y2wV297PHnmpl+Dl3zc=
=wOOx
-----END PGP SIGNATURE-----

--YiEDa0DAkWCtVeE4--


--===============7666180128674610653==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung