Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-2894

Опубликовано: 14 июл. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-2894: dbus security update (IMPORTANT)

[1:1.10.24-14.0.1]

  • fix netlink poll: error 4 (Zhenzhong Duan)

[1:1.10.24-14]

  • Fix CVE-2020-12049 (#1851991)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

dbus

1.10.24-14.0.1.el7_8

dbus-devel

1.10.24-14.0.1.el7_8

dbus-doc

1.10.24-14.0.1.el7_8

dbus-libs

1.10.24-14.0.1.el7_8

dbus-tests

1.10.24-14.0.1.el7_8

dbus-x11

1.10.24-14.0.1.el7_8

Oracle Linux x86_64

dbus

1.10.24-14.0.1.el7_8

dbus-devel

1.10.24-14.0.1.el7_8

dbus-doc

1.10.24-14.0.1.el7_8

dbus-libs

1.10.24-14.0.1.el7_8

dbus-tests

1.10.24-14.0.1.el7_8

dbus-x11

1.10.24-14.0.1.el7_8

Связанные CVE

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.

CVSS3: 6.5
redhat
больше 5 лет назад

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.

CVSS3: 5.5
nvd
больше 5 лет назад

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.

CVSS3: 5.5
debian
больше 5 лет назад

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServe ...

suse-cvrf
больше 4 лет назад

Security update for dbus-1