Date:         Wed, 11 Aug 2010 14:19:07 -0500
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA Moderate: dbus-glib on SL5.x i386/x86_64
Comments: To: "scientific-linux-errata@fnal.gov"
          

Synopsis:	Moderate: dbus-glib security update
Issue date:	2010-08-10
CVE Names:	CVE-2010-1172

It was discovered that dbus-glib did not enforce the "access" flag on
exported GObject properties. If such a property were read/write 
internally but specified as read-only externally, a malicious, local 
user could use this flaw to modify that property of an application. Such 
a change could impact the application's behavior (for example, if an IP 
address were changed the network may not come up properly after reboot) 
and possibly lead to a denial of service. (CVE-2010-1172)

Due to the way dbus-glib translates an application's XML definitions of
service interfaces and properties into C code at application build time,
applications built against dbus-glib that use read-only properties 
needed to be rebuilt to fully fix the flaw. As such, this update 
provides NetworkManager packages that have been rebuilt against the 
updated dbus-glib packages. No other applications shipped with 
Scientific Linux 5 were affected.

Running instances of NetworkManager must be restarted (service 
NetworkManager restart) for this update to take effect.

SL 5.x

     SRPMS:
NetworkManager-0.7.0-10.el5_5.1.src.rpm
dbus-glib-0.73-10.el5_5.src.rpm
     i386:
dbus-glib-0.73-10.el5_5.i386.rpm
dbus-glib-devel-0.73-10.el5_5.i386.rpm
NetworkManager-0.7.0-10.el5_5.1.i386.rpm
NetworkManager-devel-0.7.0-10.el5_5.1.i386.rpm
NetworkManager-glib-0.7.0-10.el5_5.1.i386.rpm
NetworkManager-glib-devel-0.7.0-10.el5_5.1.i386.rpm
NetworkManager-gnome-0.7.0-10.el5_5.1.i386.rpm
     x86_64:
dbus-glib-0.73-10.el5_5.i386.rpm
dbus-glib-0.73-10.el5_5.x86_64.rpm
dbus-glib-devel-0.73-10.el5_5.i386.rpm
dbus-glib-devel-0.73-10.el5_5.x86_64.rpm
NetworkManager-0.7.0-10.el5_5.1.i386.rpm
NetworkManager-0.7.0-10.el5_5.1.x86_64.rpm
NetworkManager-devel-0.7.0-10.el5_5.1.i386.rpm
NetworkManager-devel-0.7.0-10.el5_5.1.x86_64.rpm
NetworkManager-glib-0.7.0-10.el5_5.1.i386.rpm
NetworkManager-glib-0.7.0-10.el5_5.1.x86_64.rpm
NetworkManager-glib-devel-0.7.0-10.el5_5.1.i386.rpm
NetworkManager-glib-devel-0.7.0-10.el5_5.1.x86_64.rpm
NetworkManager-gnome-0.7.0-10.el5_5.1.x86_64.rpm

-Connie Sieh
-Troy Dawson

SciLinux: CVE-2010-1172 Moderate: dbus-glib SL5.x i386/x86_64

Moderate: dbus-glib security update

Summary

internally but specified as read-only externally, a malicious, localuser could use this flaw to modify that property of an application. Sucha change could impact the application's behavior (for example, if an IPaddress were changed the network may not come up properly after reboot)and possibly lead to a denial of service. (CVE-2010-1172)Due to the way dbus-glib translates an application's XML definitions ofservice interfaces and properties into C code at application build time,applications built against dbus-glib that use read-only propertiesneeded to be rebuilt to fully fix the flaw. As such, this updateprovides NetworkManager packages that have been rebuilt against theupdated dbus-glib packages. No other applications shipped withScientific Linux 5 were affected.Running instances of NetworkManager must be restarted (serviceNetworkManager restart) for this update to take effect.SL 5.xSRPMS:NetworkManager-0.7.0-10.el5_5.1.src.rpmdbus-glib-0.73-10.el5_5.src.rpmi386:dbus-glib-0.73-10.el5_5.i386.rpmdbus-glib-devel-0.73-10.el5_5.i386.rpmNetworkManager-0.7.0-10.el5_5.1.i386.rpmNetworkManager-devel-0.7.0-10.el5_5.1.i386.rpmNetworkManager-glib-0.7.0-10.el5_5.1.i386.rpmNetworkManager-glib-devel-0.7.0-10.el5_5.1.i386.rpmNetworkManager-gnome-0.7.0-10.el5_5.1.i386.rpmx86_64:dbus-glib-0.73-10.el5_5.i386.rpmdbus-glib-0.73-10.el5_5.x86_64.rpmdbus-glib-devel-0.73-10.el5_5.i386.rpmdbus-glib-devel-0.73-10.el5_5.x86_64.rpmNetworkManager-0.7.0-10.el5_5.1.i386.rpmNetworkManager-0.7.0-10.el5_5.1.x86_64.rpmNetworkManager-devel-0.7.0-10.el5_5.1.i386.rpmNetworkManager-devel-0.7.0-10.el5_5.1.x86_64.rpmNetworkManager-glib-0.7.0-10.el5_5.1.i386.rpmNetworkManager-glib-0.7.0-10.el5_5.1.x86_64.rpmNetworkManager-glib-devel-0.7.0-10.el5_5.1.i386.rpmNetworkManager-glib-devel-0.7.0-10.el5_5.1.x86_64.rpmNetworkManager-gnome-0.7.0-10.el5_5.1.x86_64.rpm-Connie Sieh-Troy Dawson



Security Fixes

Severity
Issued Date: : 2010-08-10
CVE Names: CVE-2010-1172
It was discovered that dbus-glib did not enforce the "access" flag on
exported GObject properties. If such a property were read/write

Related News