MGASA-2020-0262 - Updated dbus packages fix security vulnerability

Publication date: 15 Jun 2020
URL: https://advisories.mageia.org/MGASA-2020-0262.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-12049

The updated packages fix a security vulnerability:
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer
in libdbus, as used in dbus-daemon, leaks file descriptors when a message
exceeds the per-message file descriptor limit. A local attacker with
access to the D-Bus system bus or another system service's private
AF_UNIX socket could use this to make the system service reach its file
descriptor limit, denying service to subsequent D-Bus clients. 
(CVE-2020-12049)

References:
- https://bugs.mageia.org/show_bug.cgi?id=26735
- https://www.openwall.com/lists/oss-security/2020/06/04/3
- https://www.debian.org/lts/security/2020/dla-2235
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12049

SRPMS:
- 7/core/dbus-1.13.8-4.2.mga7

Mageia 2020-0262: dbus security update

The updated packages fix a security vulnerability: An issue was discovered in dbus >= 1.3.0 before 1.12.18

Summary

The updated packages fix a security vulnerability: An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients. (CVE-2020-12049)

References

- https://bugs.mageia.org/show_bug.cgi?id=26735

- https://www.openwall.com/lists/oss-security/2020/06/04/3

- https://www.debian.org/lts/security/2020/dla-2235

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12049

Resolution

MGASA-2020-0262 - Updated dbus packages fix security vulnerability

SRPMS

- 7/core/dbus-1.13.8-4.2.mga7

Severity
Publication date: 15 Jun 2020
URL: https://advisories.mageia.org/MGASA-2020-0262.html
Type: security
CVE: CVE-2020-12049

Related News