USN-4398-2: DBus vulnerability
dbus vulnerability
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 ESM
- Ubuntu 12.04 ESM
Summary
DBus could be made to crash if it received specially crafted input.
Software Description
- dbus – simple interprocess messaging system
Details
USN-4398-1 fixed a vulnerability in DBus. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Kevin Backhouse discovered that DBus incorrectly handled file descriptors.
A local attacker could possibly use this issue to cause DBus to crash,
resulting in a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
- Ubuntu 14.04 ESM
- libdbus-1-3 – 1.6.18-0ubuntu4.5+esm2
- Ubuntu 12.04 ESM
- libdbus-1-3 – 1.4.18-1ubuntu1.10
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
After a standard system update you need to reboot your computer to make
all the necessary changes.
References
Source: USN-4398-2: DBus vulnerability