Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2020.1979 dbus security update 8 June 2020 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: dbus Publisher: Debian Operating System: Debian GNU/Linux 8 UNIX variants (UNIX, Linux, OSX) Impact/Access: Denial of Service -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2020-12049 Original Bulletin: https://www.debian.org/lts/security/2020/dla-2235 Comment: This advisory references vulnerabilities in products which run on platforms other than Debian. It is recommended that administrators running dbus check for an updated version of the software for their operating system. - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Package : dbus Version : 1.8.22-0+deb8u3 CVE ID : CVE-2020-12049 It was discovered that there was a file descriptor leak in the D-Bus message bus. An unprivileged local attacker could use this to attack the system DBus daemon, leading to denial of service for all users of the machine. For Debian 8 "Jessie", this issue has been fixed in dbus version 1.8.22-0+deb8u3. We recommend that you upgrade your dbus packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Regards, - - -- ,''`. : :' : Chris Lamb `. `'` lamby@debian.org / chris-lamb.co.uk `- - -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl7aZbIACgkQHpU+J9Qx HliT9hAAtzQWcjADdHxVrfa7SoFLS3KCxEj+ekLMMaTBVZFZYM1lV+ZnN+dLK/6s Y0hZfrdoGyqxUL/qVGZA4qDqCmnE52CDmIgwNyK9EEc/d2QwvDMxawyE9aAK1EZC P0xAkDKwJCH0KnCs6UHZoqbPSkRqV62nUJprxhQ/Us7xz8AySjgdrrXt8oD1xE+b d+nbPMd5QkGn6QKKE9bObAZliEZ8oyRrL1aTsVZZft4sCGtxeINyL+zmV5U+iOYU 4Ff93IlJrG0hTfOXPKCsyTT+jCUeZ/1gVw25Bp8Ct9JZQJKWDAXSdkBkJoQGd0gE oF5gXRpcHo00/u2CTAGvho9RvVzFOxD3TaQYOdLnnIRv3Hea8zB+FFZEfthTd6Px fQF9vFjnKjWJ7UPcfek6PVje5o9qETRy2E4T7o9rRfa1JU4YIT2P8+xCWgDcFxWN wzXcSApgSPrcDV/LNAWcc50qHrJePvnsJfM66Kab48+bQH7T+hSJfs/D3nAKIrG2 2EquJswME2rO0MLYlbjt0XNPD0/BovhqdRVV4Tpdm4KuBBVx0H6MZglIGni+ySJI Ndz8D7nHSfE2tdgcF6F4avHMCKWSCtC9DTv2R3znbmmUEiXdkpLwKtRksT7dd65t ujHr7Ykd5F2ity9reIl7lDvnEzljARbavcOQ4G6Q/gzoYldev6I= =5ek1 - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXt16L+NLKJtyKPYoAQjlDRAAkcRIjxmQTpkTvolewnCalXM009lOV8lv k1lLP0fsuETY2I1EaCaX3VDkBSI3IVKMMhGqvdNej+/F5PGbMZel2wxwL+FPzYJz TN/Mn1dA2xosntZAiau9N1NlGuuRu5JpBzy+P+wr1lD+q/WkaCO+8KDo0ClC9fky tBah8xg/HxQ7SgAY4DbvFbrniTyao0APafGT1ijaqYhJXzfZVTxFKqEGmJw+vSQV ST0mediPmMkQBn0Zane+HPKGehb+upTVvmK7oAMuCDXhSwj/AgmUrt+R7kMJyf43 BNtqeI6984vXzV5GQgWFJnkUgrbRAq3RjHGDOGtGkugHtUkcB0+Zu2Rp9oeNfaNX wZFQtQWDrFKiPRTve3pRvX/WlNNaYVGWGE9/aBWHTAV073hbmDpQWkAglI04iIf9 8v4u4Kzmn3Ce6xSR611RQ2RX1m83KDa6k6AlqEwPS9osCwTQrC1mAGPQS5oaRgbU OmO8pJtZykcebwofKTQMfVp7R9rszdOWwF+VjonL/jnvAGHl+ClzzLaJchusXX9L XoavWGFVgzT02QaRK3Ah7R8GYHw+AU35InpYKrViSRFT6Nca1PrZelWHRSow+7Ry IoBErnediRoIcUJx2fXJ5cplKWIWXXYv0FSs2fPvoe8h0XH7E0t4510vihmddvyB AHYM3lHYzq4= =aapZ -----END PGP SIGNATURE-----