Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
198

Arch Linux: ASA-201502-10 Medium Severity: Dbus Denial Of Service

The package dbus before version 1.8.16-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201502-10 ========================================= Severity: Medium Date : 2015-02-10 CVE-ID : CVE-2015-0245 Package : dbus Type : denial of service Remote : No Link : https://wiki.archlinux.org/title/CVE Summary ====== The package dbus before version 1.8.16-1 is vulnerable to denial of service. Resolution ========= Upgrade to 1.8.16-1. # pacman -Syu "dbus> =1.8.16-1" The problem has been fixed upstream in version 1.8.16. Workaround ========= None. Description ========== Systemd sends back an ActivationFailure D-Bus signal if the activation fails. However, when it receives these signals, dbus-daemon does not verify that the signal actually came from systemd. A malicious local user could send repeated ActivationFailure signals in the hope that it would "win the race" with the genuine signal, causing D-Bus to send back an error to the client that requested activation. Impact ===== A local attacker could send repeated ActivationFailure signals, causing D-Bus to potentially send back an error to the client that requested activation resulting in denial of service. References ========= https://lists.freedesktop.org/archives/dbus/2015-February/016553.html https://www.cve.org/CVERecord?id=CVE-2015-0245 . Arch Linux Security Bulletin ASA-202303-15 addresses a notable moderate risk denial of service vulnerability in dbus. It's advised to upgrade for safety.. Arch Linux, dbus upgrade, denial of service. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Feb 10, 2015 Medium ArchLinux
198

Arch Linux 2014-11-28 Medium Severity Dbus Denial Of Service

The package dbus before version 1.8.10-1 is vulnerable to denial of service via file descriptor exhaustion. . Arch Linux Security Advisory ASA-201411-28 ========================================= Severity: Medium Date : 2014-11-23 CVE-ID : CVE-2014-7824 Package : dbus Type : denial of service Remote : No Link : https://wiki.archlinux.org/title/CVE-2014 Summary ====== The package dbus before version 1.8.10-1 is vulnerable to denial of service via file descriptor exhaustion. Resolution ========= Upgrade to 1.8.10-1. # pacman -Syu "dbus> =1.8.10-1" The problem has been fixed upstream in version 1.8.10. Workaround ========= None. Description ========== The patch issued by the D-Bus maintainers for CVE-2014-3636 was based on incorrect reasoning and does not fully prevent the attack described in the impact section below. Preventing that attack requires raising the system dbus-daemon's RLIMIT_NOFILE (ulimit -n) to a higher value. Impact ===== A local attacker is able to queue up the maximum allowed number of file descriptors to reach the system dbus-daemon's RLIMIT_NOFILE resulting in a denial of service in two ways: - new clients would be unable to connect to the dbus-daemon - when receiving a subsequent message from a non-malicious client that contained a fd, dbus-daemon would receive the MSG_CTRUNC flag, indicating that the list of fds was truncated; kernel fd-passing APIs do not provide any way to recover from that, so dbus-daemon responds to MSG_CTRUNC by disconnecting the sender, causing denial of service to that sender References ========= https://www.cve.org/CVERecord?id=CVE-2014-7824 https://www.openwall.com/lists/oss-security/2014/11/10/2 . The Arch Linux Security Advisory ASA-201401-29 highlights a critical gnome-shell vulnerability that may enable unauthorized access, detailing the flaw and mitigation actions.. Arch Linux, Dbus Security, Denial Of Service Issue. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Nov 24, 2014 Medium ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here