Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | |||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.702971 |
Categoría: | Debian Local Security Checks |
Título: | Debian Security Advisory DSA 2971-1 (dbus - security update) |
Resumen: | Several vulnerabilities have been discovered in dbus, an asynchronous;inter-process communication system. The Common Vulnerabilities and;Exposures project identifies the following problems:;;CVE-2014-3477;Alban Crequy at Collabora Ltd. discovered that dbus-daemon sends an;AccessDenied error to the service instead of a client when the;client is prohibited from accessing the service. A local attacker;could use this flaw to cause a bus-activated service that is not;currently running to attempt to start, and fail, denying other users;access to this service.;;CVE-2014-3532;Alban Crequy at Collabora Ltd. discovered a bug in dbus-daemon's;support for file descriptor passing. A malicious process could force;system services or user applications to be disconnected from the;D-Bus system by sending them a message containing a file descriptor,;leading to a denial of service.;;CVE-2014-3533;Alban Crequy at Collabora Ltd. and Alejandro Martínez Suárez;discovered that a malicious process could force services to be;disconnected from the D-Bus system by causing dbus-daemon to attempt;to forward invalid file descriptors to a victim process, leading to;a denial of service. |
Descripción: | Summary: Several vulnerabilities have been discovered in dbus, an asynchronous inter-process communication system. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2014-3477 Alban Crequy at Collabora Ltd. discovered that dbus-daemon sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service. A local attacker could use this flaw to cause a bus-activated service that is not currently running to attempt to start, and fail, denying other users access to this service. CVE-2014-3532 Alban Crequy at Collabora Ltd. discovered a bug in dbus-daemon's support for file descriptor passing. A malicious process could force system services or user applications to be disconnected from the D-Bus system by sending them a message containing a file descriptor, leading to a denial of service. CVE-2014-3533 Alban Crequy at Collabora Ltd. and Alejandro Martínez Suárez discovered that a malicious process could force services to be disconnected from the D-Bus system by causing dbus-daemon to attempt to forward invalid file descriptors to a victim process, leading to a denial of service. Affected Software/OS: dbus on Debian Linux Solution: For the stable distribution (wheezy), these problems have been fixed in version 1.6.8-1+deb7u3. For the unstable distribution (sid), these problems have been fixed in version 1.8.6-1. We recommend that you upgrade your dbus packages. CVSS Score: 2.1 CVSS Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-3477 BugTraq ID: 67986 http://www.securityfocus.com/bid/67986 Debian Security Information: DSA-2971 (Google Search) http://www.debian.org/security/2014/dsa-2971 http://www.mandriva.com/security/advisories?name=MDVSA-2015:176 http://seclists.org/oss-sec/2014/q2/509 http://secunia.com/advisories/59428 http://secunia.com/advisories/59611 http://secunia.com/advisories/59798 SuSE Security Announcement: openSUSE-SU-2014:0821 (Google Search) http://lists.opensuse.org/opensuse-updates/2014-06/msg00042.html SuSE Security Announcement: openSUSE-SU-2014:0874 (Google Search) http://lists.opensuse.org/opensuse-updates/2014-07/msg00012.html SuSE Security Announcement: openSUSE-SU-2014:1239 (Google Search) http://lists.opensuse.org/opensuse-updates/2014-09/msg00049.html Common Vulnerability Exposure (CVE) ID: CVE-2014-3532 http://openwall.com/lists/oss-security/2014/07/02/4 http://secunia.com/advisories/60236 Common Vulnerability Exposure (CVE) ID: CVE-2014-3533 |
Copyright | Copyright (c) 2014 Greenbone Networks GmbH http://greenbone.net |
Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |