Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2010-0018

Опубликовано: 07 янв. 2010
Источник: oracle-oval
Платформа: Oracle Linux 5

Описание

ELSA-2010-0018: dbus security update (MODERATE)

[1.1.2-12.el5_4.1]

  • CVE-2009-1189 dbus: invalid fix for CVE-2008-3834

Обновленные пакеты

Oracle Linux 5

Oracle Linux ia64

dbus

1.1.2-12.el5_4.1

dbus-devel

1.1.2-12.el5_4.1

dbus-libs

1.1.2-12.el5_4.1

dbus-x11

1.1.2-12.el5_4.1

Oracle Linux x86_64

dbus

1.1.2-12.el5_4.1

dbus-devel

1.1.2-12.el5_4.1

dbus-libs

1.1.2-12.el5_4.1

dbus-x11

1.1.2-12.el5_4.1

Oracle Linux i386

dbus

1.1.2-12.el5_4.1

dbus-devel

1.1.2-12.el5_4.1

dbus-libs

1.1.2-12.el5_4.1

dbus-x11

1.1.2-12.el5_4.1

Связанные CVE

Связанные уязвимости

ubuntu
около 16 лет назад

The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.

redhat
около 16 лет назад

The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.

nvd
около 16 лет назад

The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.

debian
около 16 лет назад

The _dbus_validate_signature_with_reason function (dbus-marshal-valida ...

github
около 3 лет назад

The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.