what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Ubuntu Security Notice USN-1576-2

Ubuntu Security Notice USN-1576-2
Posted Oct 5, 2012
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1576-2 - USN-1576-1 fixed vulnerabilities in DBus. The update caused a regression for certain services launched from the activation helper, and caused an unclean shutdown on upgrade. This update fixes the problem. Sebastian Krahmer discovered that DBus incorrectly handled environment variables when running with elevated privileges. A local attacker could possibly exploit this flaw with a setuid binary and gain root privileges. Various other issues were also addressed.

tags | advisory, local, root, vulnerability
systems | linux, ubuntu
advisories | CVE-2012-3524
SHA-256 | b76b46abec3e894741300d77a561d5b8163b65ee2dd9a52368e6aafd32e9c0b1

Ubuntu Security Notice USN-1576-2

Change Mirror Download
============================================================================
Ubuntu Security Notice USN-1576-2
October 04, 2012

dbus regressions
============================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

DBus could be made to run programs as an administrator.

Software Description:
- dbus: simple interprocess messaging system

Details:

USN-1576-1 fixed vulnerabilities in DBus. The update caused a regression
for certain services launched from the activation helper, and caused an
unclean shutdown on upgrade. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Sebastian Krahmer discovered that DBus incorrectly handled environment
variables when running with elevated privileges. A local attacker could
possibly exploit this flaw with a setuid binary and gain root privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
dbus 1.4.18-1ubuntu1.3
libdbus-1-3 1.4.18-1ubuntu1.3

Ubuntu 11.10:
dbus 1.4.14-1ubuntu1.3
libdbus-1-3 1.4.14-1ubuntu1.3

Ubuntu 11.04:
dbus 1.4.6-1ubuntu6.4
libdbus-1-3 1.4.6-1ubuntu6.4

Ubuntu 10.04 LTS:
dbus 1.2.16-2ubuntu4.7
libdbus-1-3 1.2.16-2ubuntu4.7

Ubuntu 8.04 LTS:
dbus 1.1.20-1ubuntu3.9
libdbus-1-3 1.1.20-1ubuntu3.9

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1576-2
http://www.ubuntu.com/usn/usn-1576-1
CVE-2012-3524

Package Information:
https://launchpad.net/ubuntu/+source/dbus/1.4.18-1ubuntu1.3
https://launchpad.net/ubuntu/+source/dbus/1.4.14-1ubuntu1.3
https://launchpad.net/ubuntu/+source/dbus/1.4.6-1ubuntu6.4
https://launchpad.net/ubuntu/+source/dbus/1.2.16-2ubuntu4.7
https://launchpad.net/ubuntu/+source/dbus/1.1.20-1ubuntu3.9
Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    28 Files
  • 7
    May 7th
    0 Files
  • 8
    May 8th
    0 Files
  • 9
    May 9th
    0 Files
  • 10
    May 10th
    0 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    0 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    0 Files
  • 17
    May 17th
    0 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close