-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2020.1979
                           dbus security update
                                8 June 2020

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           dbus
Publisher:         Debian
Operating System:  Debian GNU/Linux 8
                   UNIX variants (UNIX, Linux, OSX)
Impact/Access:     Denial of Service -- Existing Account
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-12049  

Original Bulletin: 
   https://www.debian.org/lts/security/2020/dla-2235

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Debian. It is recommended that administrators 
         running dbus check for an updated version of the software for their
         operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : dbus
Version        : 1.8.22-0+deb8u3
CVE ID         : CVE-2020-12049

It was discovered that there was a file descriptor leak in the D-Bus
message bus.

An unprivileged local attacker could use this to attack the system
DBus daemon, leading to denial of service for all users of the
machine.

For Debian 8 "Jessie", this issue has been fixed in dbus version
1.8.22-0+deb8u3.

We recommend that you upgrade your dbus packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Regards,

- - -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl7aZbIACgkQHpU+J9Qx
HliT9hAAtzQWcjADdHxVrfa7SoFLS3KCxEj+ekLMMaTBVZFZYM1lV+ZnN+dLK/6s
Y0hZfrdoGyqxUL/qVGZA4qDqCmnE52CDmIgwNyK9EEc/d2QwvDMxawyE9aAK1EZC
P0xAkDKwJCH0KnCs6UHZoqbPSkRqV62nUJprxhQ/Us7xz8AySjgdrrXt8oD1xE+b
d+nbPMd5QkGn6QKKE9bObAZliEZ8oyRrL1aTsVZZft4sCGtxeINyL+zmV5U+iOYU
4Ff93IlJrG0hTfOXPKCsyTT+jCUeZ/1gVw25Bp8Ct9JZQJKWDAXSdkBkJoQGd0gE
oF5gXRpcHo00/u2CTAGvho9RvVzFOxD3TaQYOdLnnIRv3Hea8zB+FFZEfthTd6Px
fQF9vFjnKjWJ7UPcfek6PVje5o9qETRy2E4T7o9rRfa1JU4YIT2P8+xCWgDcFxWN
wzXcSApgSPrcDV/LNAWcc50qHrJePvnsJfM66Kab48+bQH7T+hSJfs/D3nAKIrG2
2EquJswME2rO0MLYlbjt0XNPD0/BovhqdRVV4Tpdm4KuBBVx0H6MZglIGni+ySJI
Ndz8D7nHSfE2tdgcF6F4avHMCKWSCtC9DTv2R3znbmmUEiXdkpLwKtRksT7dd65t
ujHr7Ykd5F2ity9reIl7lDvnEzljARbavcOQ4G6Q/gzoYldev6I=
=5ek1
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXt16L+NLKJtyKPYoAQjlDRAAkcRIjxmQTpkTvolewnCalXM009lOV8lv
k1lLP0fsuETY2I1EaCaX3VDkBSI3IVKMMhGqvdNej+/F5PGbMZel2wxwL+FPzYJz
TN/Mn1dA2xosntZAiau9N1NlGuuRu5JpBzy+P+wr1lD+q/WkaCO+8KDo0ClC9fky
tBah8xg/HxQ7SgAY4DbvFbrniTyao0APafGT1ijaqYhJXzfZVTxFKqEGmJw+vSQV
ST0mediPmMkQBn0Zane+HPKGehb+upTVvmK7oAMuCDXhSwj/AgmUrt+R7kMJyf43
BNtqeI6984vXzV5GQgWFJnkUgrbRAq3RjHGDOGtGkugHtUkcB0+Zu2Rp9oeNfaNX
wZFQtQWDrFKiPRTve3pRvX/WlNNaYVGWGE9/aBWHTAV073hbmDpQWkAglI04iIf9
8v4u4Kzmn3Ce6xSR611RQ2RX1m83KDa6k6AlqEwPS9osCwTQrC1mAGPQS5oaRgbU
OmO8pJtZykcebwofKTQMfVp7R9rszdOWwF+VjonL/jnvAGHl+ClzzLaJchusXX9L
XoavWGFVgzT02QaRK3Ah7R8GYHw+AU35InpYKrViSRFT6Nca1PrZelWHRSow+7Ry
IoBErnediRoIcUJx2fXJ5cplKWIWXXYv0FSs2fPvoe8h0XH7E0t4510vihmddvyB
AHYM3lHYzq4=
=aapZ
-----END PGP SIGNATURE-----