Updated dbus packages fix multiple security vulnerabilities
Publication date: 07 Oct 2014Modification date: 07 Oct 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-3635 , CVE-2014-3636 , CVE-2014-3637 , CVE-2014-3638 , CVE-2014-3639
Description
Updated dbus packages fixes the following security issues: Alban Crequy and Simon McVittie discovered several vulnerabilities in the D-Bus message daemon: On 64-bit platforms, file descriptor passing could be abused by local users to cause heap corruption in dbus-daemon, leading to a crash, or potentially to arbitrary code execution (CVE-2014-3635). A denial-of-service vulnerability in dbus-daemon allowed local attackers to prevent new connections to dbus-daemon, or disconnect existing clients, by exhausting descriptor limits (CVE-2014-3636). Malicious local users could create D-Bus connections to dbus-daemon which could not be terminated by killing the participating processes, resulting in a denial-of-service vulnerability (CVE-2014-3637). dbus-daemon suffered from a denial-of-service vulnerability in the code which tracks which messages expect a reply, allowing local attackers to reduce the performance of dbus-daemon (CVE-2014-3638). dbus-daemon did not properly reject malicious connections from local users, resulting in a denial-of-service vulnerability (CVE-2014-3639).
References
- https://bugs.mageia.org/show_bug.cgi?id=14102
- http://openwall.com/lists/oss-security/2014/09/16/9
- https://www.debian.org/security/2014/dsa-3026
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3635
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3636
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3637
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3638
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3639
SRPMS
4/core
- dbus-1.6.18-1.4.mga4
3/core
- dbus-1.6.8-4.5.mga3