Summary
Ubuntu Update for Linux kernel vulnerabilities USN-653-1
Solution
Please Install the Updated Packages.
Insight
Havoc Pennington discovered that the D-Bus daemon did not correctly validate certain security policies. If a local user sent a specially crafted D-Bus request, they could bypass security policies that had a "
send_interface"
defined. (CVE-2008-0595)
It was discovered that the D-Bus library did not correctly validate certain corrupted signatures. If a local user sent a specially crafted D-Bus request, they could crash applications linked against the D-Bus library, leading to a denial of service. (CVE-2008-3834)
Affected
dbus vulnerabilities on Ubuntu 6.06 LTS ,
Ubuntu 7.04 ,
Ubuntu 7.10 ,
Ubuntu 8.04 LTS
Severity
Classification
-
CVE CVE-2008-0595, CVE-2008-3834 -
CVSS Base Score: 4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities