Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.702971
Categoría:Debian Local Security Checks
Título:Debian Security Advisory DSA 2971-1 (dbus - security update)
Resumen:Several vulnerabilities have been discovered in dbus, an asynchronous;inter-process communication system. The Common Vulnerabilities and;Exposures project identifies the following problems:;;CVE-2014-3477;Alban Crequy at Collabora Ltd. discovered that dbus-daemon sends an;AccessDenied error to the service instead of a client when the;client is prohibited from accessing the service. A local attacker;could use this flaw to cause a bus-activated service that is not;currently running to attempt to start, and fail, denying other users;access to this service.;;CVE-2014-3532;Alban Crequy at Collabora Ltd. discovered a bug in dbus-daemon's;support for file descriptor passing. A malicious process could force;system services or user applications to be disconnected from the;D-Bus system by sending them a message containing a file descriptor,;leading to a denial of service.;;CVE-2014-3533;Alban Crequy at Collabora Ltd. and Alejandro Martínez Suárez;discovered that a malicious process could force services to be;disconnected from the D-Bus system by causing dbus-daemon to attempt;to forward invalid file descriptors to a victim process, leading to;a denial of service.
Descripción:Summary:
Several vulnerabilities have been discovered in dbus, an asynchronous
inter-process communication system. The Common Vulnerabilities and
Exposures project identifies the following problems:

CVE-2014-3477
Alban Crequy at Collabora Ltd. discovered that dbus-daemon sends an
AccessDenied error to the service instead of a client when the
client is prohibited from accessing the service. A local attacker
could use this flaw to cause a bus-activated service that is not
currently running to attempt to start, and fail, denying other users
access to this service.

CVE-2014-3532
Alban Crequy at Collabora Ltd. discovered a bug in dbus-daemon's
support for file descriptor passing. A malicious process could force
system services or user applications to be disconnected from the
D-Bus system by sending them a message containing a file descriptor,
leading to a denial of service.

CVE-2014-3533
Alban Crequy at Collabora Ltd. and Alejandro Martínez Suárez
discovered that a malicious process could force services to be
disconnected from the D-Bus system by causing dbus-daemon to attempt
to forward invalid file descriptors to a victim process, leading to
a denial of service.

Affected Software/OS:
dbus on Debian Linux

Solution:
For the stable distribution (wheezy), these problems have been fixed in
version 1.6.8-1+deb7u3.

For the unstable distribution (sid), these problems have been fixed in
version 1.8.6-1.

We recommend that you upgrade your dbus packages.

CVSS Score:
2.1

CVSS Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2014-3477
BugTraq ID: 67986
http://www.securityfocus.com/bid/67986
Debian Security Information: DSA-2971 (Google Search)
http://www.debian.org/security/2014/dsa-2971
http://www.mandriva.com/security/advisories?name=MDVSA-2015:176
http://seclists.org/oss-sec/2014/q2/509
http://secunia.com/advisories/59428
http://secunia.com/advisories/59611
http://secunia.com/advisories/59798
SuSE Security Announcement: openSUSE-SU-2014:0821 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-06/msg00042.html
SuSE Security Announcement: openSUSE-SU-2014:0874 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-07/msg00012.html
SuSE Security Announcement: openSUSE-SU-2014:1239 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-09/msg00049.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-3532
http://openwall.com/lists/oss-security/2014/07/02/4
http://secunia.com/advisories/60236
Common Vulnerability Exposure (CVE) ID: CVE-2014-3533
CopyrightCopyright (c) 2014 Greenbone Networks GmbH http://greenbone.net

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.