Date:         Fri, 8 Jan 2010 13:14:56 -0600
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA Moderate: dbus on SL5.x i386/x86_64
Comments: To: "scientific-linux-errata@fnal.gov"
          

Synopsis:	Moderate: dbus security update
Issue date:	2010-01-07
CVE Names:	CVE-2009-1189

It was discovered that the last dbus security update did not correctly 
fix the denial of service flaw in the system for sending messages 
between applications. A local user could use this flaw to send a
message with a malformed signature to the bus, causing the bus (and,
consequently, any process using libdbus to receive messages) to abort.
(CVE-2009-1189)

Note: Users running any application providing services over the system
message bus are advised to test this update carefully before deploying 
it in production environments.

For the update to take effect, all running instances of dbus-daemon and 
all running applications using the libdbus library must be restarted, or 
the system rebooted.

SL 5.x

     SRPMS:
dbus-1.1.2-12.el5_4.1.src.rpm
     i386:
dbus-1.1.2-12.el5_4.1.i386.rpm
dbus-devel-1.1.2-12.el5_4.1.i386.rpm
dbus-libs-1.1.2-12.el5_4.1.i386.rpm
dbus-x11-1.1.2-12.el5_4.1.i386.rpm
     x86_64:
dbus-1.1.2-12.el5_4.1.i386.rpm
dbus-1.1.2-12.el5_4.1.x86_64.rpm
dbus-devel-1.1.2-12.el5_4.1.i386.rpm
dbus-devel-1.1.2-12.el5_4.1.x86_64.rpm
dbus-libs-1.1.2-12.el5_4.1.i386.rpm
dbus-libs-1.1.2-12.el5_4.1.x86_64.rpm
dbus-x11-1.1.2-12.el5_4.1.x86_64.rpm

-Connie Sieh
-Troy Dawson

SciLinux: CVE-2009-1189 Moderate: dbus SL5.x i386/x86_64

Moderate: dbus security update

Summary

between applications. A local user could use this flaw to send amessage with a malformed signature to the bus, causing the bus (and,consequently, any process using libdbus to receive messages) to abort.(CVE-2009-1189)Note: Users running any application providing services over the systemmessage bus are advised to test this update carefully before deployingit in production environments.For the update to take effect, all running instances of dbus-daemon andall running applications using the libdbus library must be restarted, orthe system rebooted.SL 5.xSRPMS:dbus-1.1.2-12.el5_4.1.src.rpmi386:dbus-1.1.2-12.el5_4.1.i386.rpmdbus-devel-1.1.2-12.el5_4.1.i386.rpmdbus-libs-1.1.2-12.el5_4.1.i386.rpmdbus-x11-1.1.2-12.el5_4.1.i386.rpmx86_64:dbus-1.1.2-12.el5_4.1.i386.rpmdbus-1.1.2-12.el5_4.1.x86_64.rpmdbus-devel-1.1.2-12.el5_4.1.i386.rpmdbus-devel-1.1.2-12.el5_4.1.x86_64.rpmdbus-libs-1.1.2-12.el5_4.1.i386.rpmdbus-libs-1.1.2-12.el5_4.1.x86_64.rpmdbus-x11-1.1.2-12.el5_4.1.x86_64.rpm-Connie Sieh-Troy Dawson



Security Fixes

Severity
Issued Date: : 2010-01-07
CVE Names: CVE-2009-1189
It was discovered that the last dbus security update did not correctly
fix the denial of service flaw in the system for sending messages

Related News