Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-3014

Опубликовано: 23 июл. 2020
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2020-3014: dbus security update (IMPORTANT)

[1.12.8-10.0.1.el8_2]

  • fix netlink poll: error 4 (Zhenzhong Duan)

[1:1.12.8-10]

  • Fix CVE-2020-12049 (#1851996)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

dbus

1.12.8-10.0.1.el8_2

dbus-common

1.12.8-10.0.1.el8_2

dbus-daemon

1.12.8-10.0.1.el8_2

dbus-devel

1.12.8-10.0.1.el8_2

dbus-libs

1.12.8-10.0.1.el8_2

dbus-tools

1.12.8-10.0.1.el8_2

dbus-x11

1.12.8-10.0.1.el8_2

Oracle Linux x86_64

dbus

1.12.8-10.0.1.el8_2

dbus-common

1.12.8-10.0.1.el8_2

dbus-daemon

1.12.8-10.0.1.el8_2

dbus-devel

1.12.8-10.0.1.el8_2

dbus-libs

1.12.8-10.0.1.el8_2

dbus-tools

1.12.8-10.0.1.el8_2

dbus-x11

1.12.8-10.0.1.el8_2

Связанные CVE

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.

CVSS3: 6.5
redhat
больше 5 лет назад

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.

CVSS3: 5.5
nvd
больше 5 лет назад

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.

CVSS3: 5.5
debian
больше 5 лет назад

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServe ...

suse-cvrf
больше 4 лет назад

Security update for dbus-1