Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2012-1261

Опубликовано: 13 сент. 2012
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2012-1261: dbus security update (MODERATE)

[1:1.2.24-7.0.1.el6_3 ]

  • fix netlink poll: error 4 (Zhenzhong Duan)

[1:1.2.24-7]

  • Resolves: #854821

[1:1.2.24-6]

  • Apply patches for CVE-2011-2200
  • Resolves: #725314

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

dbus

1.2.24-7.0.1.el6_3

dbus-devel

1.2.24-7.0.1.el6_3

dbus-doc

1.2.24-7.0.1.el6_3

dbus-libs

1.2.24-7.0.1.el6_3

dbus-x11

1.2.24-7.0.1.el6_3

Oracle Linux i686

dbus

1.2.24-7.0.1.el6_3

dbus-devel

1.2.24-7.0.1.el6_3

dbus-doc

1.2.24-7.0.1.el6_3

dbus-libs

1.2.24-7.0.1.el6_3

dbus-x11

1.2.24-7.0.1.el6_3

Связанные CVE

Связанные уязвимости

ubuntu
почти 13 лет назад

libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."

redhat
почти 13 лет назад

libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."

nvd
почти 13 лет назад

libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."

debian
почти 13 лет назад

libdbus 1.5.x and earlier, when used in setuid or other privileged pro ...

github
больше 3 лет назад

libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."