MGASA-2014-0266
Dashboard / Vulnerabilities / MGASA-2014-0266
Summary: Updated dbus packages fix security vulnerability
Details: Updated dbus packages fix security vulnerability: A denial of service vulnerability in D-Bus before 1.6.20 allows a local attacker to cause a bus-activated service that is not currently running to attempt to start, and fail, denying other users access to this service Additionally, in highly unusual environments the same flaw could lead to a side channel between processes that should not be able to communicate (CVE-2014-3477).
References: https://advisories.mageia.org/MGASA-2014-0266.html, https://bugs.mageia.org/show_bug.cgi?id=13513, http://lists.freedesktop.org/archives/dbus/2014-June/016220.html
Affected packages
Package
Name: dbus
Purl: pkg:rpm/mageia/dbus?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
