Mageia 2020-0262: dbus security update
Summary
The updated packages fix a security vulnerability:
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer
in libdbus, as used in dbus-daemon, leaks file descriptors when a message
exceeds the per-message file descriptor limit. A local attacker with
access to the D-Bus system bus or another system service's private
AF_UNIX socket could use this to make the system service reach its file
descriptor limit, denying service to subsequent D-Bus clients.
(CVE-2020-12049)
References
- https://bugs.mageia.org/show_bug.cgi?id=26735
- https://www.openwall.com/lists/oss-security/2020/06/04/3
- https://www.debian.org/lts/security/2020/dla-2235
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12049
Resolution
MGASA-2020-0262 - Updated dbus packages fix security vulnerability
SRPMS
- 7/core/dbus-1.13.8-4.2.mga7