|
|
Log in / Subscribe / Register

dbus: denial of service

Package(s):dbus CVE #(s):CVE-2015-0245
Created:February 12, 2015 Updated:January 11, 2017
Description: From the Debian advisory:

Simon McVittie discovered a local denial of service flaw in dbus, an asynchronous inter-process communication system. On systems with systemd-style service activation, dbus-daemon does not prevent forged ActivationFailure messages from non-root processes. A malicious local user could use this flaw to trick dbus-daemon into thinking that systemd failed to activate a system service, resulting in an error reply back to the requester.

Alerts:
openSUSE openSUSE-SU-2016:2736-1 dbus-1 2016-11-05
Ubuntu USN-3116-1 dbus 2016-11-01
Gentoo 201701-20 dbus 2017-01-11
Mandriva MDVSA-2015:176 dbus 2015-03-30
Gentoo 201503-02 dbus 2015-03-07
Fedora FEDORA-2015-2060 dbus 2015-02-19
Mageia MGASA-2015-0071 dbus 2015-02-17
openSUSE openSUSE-SU-2015:0300-1 dbus-1, 2015-02-17
Fedora FEDORA-2015-2007 dbus 2015-02-16
Debian DSA-3161-1 dbus 2015-02-11

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds