Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 14.04 LTS USN-2352-1: Critical DBus Denial Of Service Advisory

ubuntu
Calendar Grey September 22, 2014
Scroller Ubuntu
Numerous vulnerabilities were addressed in OpenSSL impacting Ubuntu 10.10, 12.10, and 14.10 LTS with urgent patches.
Several security issues were fixed in DBus.

Summary

Several security issues were fixed in DBus.

Software Description:

- dbus: simple interprocess messaging system

Details:

Simon McVittie discovered that DBus incorrectly handled the file

descriptors message limit. A local attacker could use this issue to cause

DBus to crash, resulting in a denial of service, or possibly execute

arbitrary code. This issue only applied to Ubuntu 12.04 LTS and Ubuntu

14.04 LTS. (CVE-2014-3635)

Alban Crequy discovered that DBus incorrectly handled a large number of

file descriptor messages. A local attacker could use this issue to cause

DBus to stop responding, resulting in a denial of service. This issue only

applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-3636)

Alban Crequy discovered that DBus incorrectly handled certain file

descriptor messages. A local attacker could use this issue to cause DBus

to maintain persistent connections, possibly resulting in a denial of

service. This issue only applied to Ubuntu 12.0...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  dbus                            1.6.18-0ubuntu4.2
  libdbus-1-3                     1.6.18-0ubuntu4.2

Ubuntu 12.04 LTS:
  dbus                            1.4.18-1ubuntu1.6
  libdbus-1-3                     1.4.18-1ubuntu1.6

Ubuntu 10.04 LTS:
  dbus                            1.2.16-2ubuntu4.8
  libdbus-1-3                     1.2.16-2ubuntu4.8

After a standard system update you need to reboot your computer to make all
the necessary changes.

References

https://ubuntu.com/security/notices/USN-2352-1

CVE-2014-3635, CVE-2014-3636, CVE-2014-3637, CVE-2014-3638,

CVE-2014-3639

Severity
critical
Lowest
Low
Medium
High
Critical

September 22, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.