LWN.net Logo

dbus: denial of service

Package(s):dbus CVE #(s):CVE-2011-2200
Created:July 12, 2011 Updated:August 23, 2012
Description: From the Pardus advisory:

It was found that D-BUS message bus service / messaging facility did not update the byte-order flag of the message properly by swapping the byte order of incoming messages into their native endiannes. A local, authenticated user could use this flaw to send a specially-crafted message to a system service (like Avahi or NetworkManager), using the system bus, potentially leading to disconnect of such a service from system bus (denial of service).

Alerts:
Gentoo 201110-14 2011-10-21
CentOS CESA-2011:1132 2011-09-22
Scientific Linux SL-dbus-20110809 2011-08-09
Fedora FEDORA-2011-9817 2011-07-31
Red Hat RHSA-2011:1132-01 2011-08-09
openSUSE openSUSE-SU-2011:0880-1 2011-08-08
Fedora FEDORA-2011-9891 2011-07-31
Ubuntu USN-1176-1 2011-07-26
Pardus 2011-93 2011-07-11
Mageia MGASA-2012-0233 2012-08-23
Oracle ELSA-2012-1261 2012-09-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds