Debian DSA-2971-1 : dbus - security update

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

The remote Debian host is missing a security-related update.

Description :

Several vulnerabilities have been discovered in dbus, an asynchronous
inter-process communication system. The Common Vulnerabilities and
Exposures project identifies the following problems :

- CVE-2014-3477
Alban Crequy at Collabora Ltd. discovered that
dbus-daemon sends an AccessDenied error to the service
instead of a client when the client is prohibited from
accessing the service. A local attacker could use this
flaw to cause a bus-activated service that is not
currently running to attempt to start, and fail, denying
other users access to this service.

- CVE-2014-3532
Alban Crequy at Collabora Ltd. discovered a bug in
dbus-daemon's support for file descriptor passing. A
malicious process could force system services or user
applications to be disconnected from the D-Bus system by
sending them a message containing a file descriptor,
leading to a denial of service.

- CVE-2014-3533
Alban Crequy at Collabora Ltd. and Alejandro Martínez
Suárez discovered that a malicious process could force
services to be disconnected from the D-Bus system by
causing dbus-daemon to attempt to forward invalid file
descriptors to a victim process, leading to a denial of
service.

See also :

https://security-tracker.debian.org/tracker/CVE-2014-3477
https://security-tracker.debian.org/tracker/CVE-2014-3532
https://security-tracker.debian.org/tracker/CVE-2014-3533
http://www.debian.org/security/2014/dsa-2971

Solution :

Upgrade the dbus packages.

For the stable distribution (wheezy), these problems have been fixed
in version 1.6.8-1+deb7u3.

Risk factor :

Low / CVSS Base Score : 2.1
(CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P)
CVSS Temporal Score : 1.8
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Debian Local Security Checks

Nessus Plugin ID: 76349 ()

Bugtraq ID: 67986
68337
68339

CVE ID: CVE-2014-3477
CVE-2014-3532
CVE-2014-3533