MGASA-2014-0294
Dashboard / Vulnerabilities / MGASA-2014-0294
Summary: Updated dbus packages fix multiple vulnerabilities
Details: Updated dbus packages fix security vulnerabilities: A flaw was reported in D-Bus's file descriptor passing feature. A local attacker could use this flaw to cause a service or application to disconnect from the bus, typically resulting in that service or application exiting (CVE-2014-3532). A flaw was reported in D-Bus's file descriptor passing feature. A local attacker could use this flaw to cause an invalid file descriptor to be forwarded to a service or application, causing it to disconnect from the bus, typically resulting in that service or application exiting (CVE-2014-3533).
References: https://advisories.mageia.org/MGASA-2014-0294.html, http://lists.freedesktop.org/archives/dbus/2014-July/016235.html, https://lists.fedoraproject.org/pipermail/package-announce/2014-July/135226.html, https://bugs.mageia.org/show_bug.cgi?id=13653
Affected packages
Package
Name: dbus
Purl: pkg:rpm/mageia/dbus?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
