It was discovered that the dbus_signature_validate function in
dbus, a simple interprocess messaging system, is prone to a denial of
service attack. This issue was caused by an incorrect fix for
DSA-1658-1.
For the stable distribution (lenny), this problem has been fixed in
version 1.2.1-5+lenny1.
For the oldstable distribution (etch), this problem has been fixed in
version 1.0.2-1+etch3.
Packages for ia64 and s390 will be released once they are available.
For the testing distribution (squeeze) and the unstable distribution
(sid), this problem has been fixed in version 1.2.14-1.
We recommend that you upgrade your dbus packages.
Upgrade instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
You may use an automated update ...
Get the latest Linux and open source security news straight to your inbox.