First published: Thu Jun 13 2013(Updated: )
A denial of service flaw was found in the way UNIX system D-BUS format string wrapper implementation of D-BUS, a system for sending messages between applications, used to measure the length of the provided format string and its arguments in certain circumstances. A remote attacker could supply a specially-crafted input to an application / service, utilizing the services / functionality of the libdbus library that, when processed would lead to that application / service crash. References: [1] <a href="http://www.openwall.com/lists/oss-security/2013/06/13/2">http://www.openwall.com/lists/oss-security/2013/06/13/2</a> Relevant upstream patch: [2] <a href="http://cgit.freedesktop.org/dbus/dbus/commit/?id=954d75b2b64e4799f360d2a6bf9cff6d9fee37e7">http://cgit.freedesktop.org/dbus/dbus/commit/?id=954d75b2b64e4799f360d2a6bf9cff6d9fee37e7</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/dbus | <1.4.26 | 1.4.26 |
redhat/dbus | <1.6.12 | 1.6.12 |
redhat/dbus | <1.7.4 | 1.7.4 |
Freedesktop Dbus | =1.4.0 | |
Freedesktop Dbus | =1.4.1 | |
Freedesktop Dbus | =1.4.4 | |
Freedesktop Dbus | =1.4.6 | |
Freedesktop Dbus | =1.4.8 | |
Freedesktop Dbus | =1.4.10 | |
Freedesktop Dbus | =1.4.12 | |
Freedesktop Dbus | =1.4.14 | |
Freedesktop Dbus | =1.4.16 | |
Freedesktop Dbus | =1.4.18 | |
Freedesktop Dbus | =1.4.20 | |
Freedesktop Dbus | =1.4.24 | |
Freedesktop Dbus | =1.7.0 | |
Freedesktop Dbus | =1.7.2 | |
Freedesktop Dbus | =1.6.0 | |
Freedesktop Dbus | =1.6.2 | |
Freedesktop Dbus | =1.6.4 | |
Freedesktop Dbus | =1.6.6 | |
Freedesktop Dbus | =1.6.8 | |
Freedesktop Dbus | =1.6.10 | |
Freedesktop Dbus | =1.6.16 | |
openSUSE openSUSE | =12.3 | |
D-bus Project D-bus | =1.4.0 | |
D-bus Project D-bus | =1.4.1 | |
D-bus Project D-bus | =1.4.4 | |
D-bus Project D-bus | =1.4.6 | |
D-bus Project D-bus | =1.4.8 | |
D-bus Project D-bus | =1.4.10 | |
D-bus Project D-bus | =1.4.12 | |
D-bus Project D-bus | =1.4.14 | |
D-bus Project D-bus | =1.4.16 | |
D-bus Project D-bus | =1.4.18 | |
D-bus Project D-bus | =1.4.20 | |
D-bus Project D-bus | =1.4.24 | |
D-bus Project D-bus | =1.7.0 | |
D-bus Project D-bus | =1.7.2 | |
D-bus Project D-bus | =1.6.0 | |
D-bus Project D-bus | =1.6.2 | |
D-bus Project D-bus | =1.6.4 | |
D-bus Project D-bus | =1.6.6 | |
D-bus Project D-bus | =1.6.8 | |
D-bus Project D-bus | =1.6.10 | |
D-bus Project D-bus | =1.6.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.