ac2517ed34
openSUSE Security Update: Security update for dbus-1 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2015:0111-1 Rating: moderate References: #912016 Cross-References: CVE-2012-3524 CVE-2014-8148 Affected Products: openSUSE 13.2 openSUSE 13.1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update fixes the following security issues: * CVE-2014-8148: - Do not allow calls to UpdateActivationEnvironment from uids other than the uid of the dbus-daemon. If a system service installs unsafe security policy rules that allow arbitrary method calls (such as CVE-2014-8148) then this prevents memory consumption and possible privilege escalation via UpdateActivationEnvironment. * CVE-2012-3524: Don't access environment variables (bnc#912016) References: http://support.novell.com/security/cve/CVE-2012-3524.html http://support.novell.com/security/cve/CVE-2014-8148.html https://bugzilla.suse.com/show_bug.cgi?id=912016 |
||
---|---|---|
.. | ||
DEINSTALL | ||
DESCR | ||
distinfo | ||
INSTALL | ||
Makefile |