OESA-2021-1101
Dashboard / Vulnerabilities / OESA-2021-1101
Summary: dbus security update
Details: D-Bus is a message bus system, a simple way for applications to talk to one another. In addition to interprocess communication, D-Bus helps coordinate process lifecycle; it makes it simple and reliable to code a "single instance" application or daemon, and to launch applications and daemons on demand when their services are needed. Security Fix(es): A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors(CVE-2020-35512)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1101, https://nvd.nist.gov/vuln/detail/CVE-2020-35512
Affected packages
Package
Name: dbus
Purl: pkg:rpm/openEuler/dbus&distro=openEuler-20.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
