Advisories ยป MGASA-2013-0173

Updated dbus packages fix security vulnerability

Publication date: 18 Jun 2013
Modification date: 18 Jun 2013
Type: security
Affected Mageia releases : 2 , 3
CVE: CVE-2013-2168

Description

Alexandru Cornea discovered a vulnerability in libdbus caused by an
implementation bug in _dbus_printf_string_upper_bound(). This
vulnerability can be exploited by a local user to crash system services
that use libdbus, causing denial of service. Depending on the dbus
services running, it could lead to complete system crash (CVE-2013-2168).

This problem only currently appears to affect the x86_64 version of Mageia
but we advise that all systems should be updated.
                

References

SRPMS

2/core

3/core