GLSA-202012-17 : D-Bus: Denial of service

low Nessus Plugin ID 144601

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-202012-17 (D-Bus: Denial of service)

It was discovered that D-Bus did not properly handle the situation when two usernames have the same numeric UID.
Impact :

An attacker could possibly cause a Denial of Service condition or trigger other undefined behavior, possibly including incorrect authorization decisions.
Workaround :

There is no known workaround at this time.

Solution

All D-Bus users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=sys-apps/dbus-1.12.20'

See Also

http://www.nessus.org/u?6fa2dd89

https://security.gentoo.org/glsa/202012-17

Plugin Details

Severity: Low

ID: 144601

File Name: gentoo_GLSA-202012-17.nasl

Version: 1.1

Type: local

Published: 12/24/2020

Updated: 12/24/2020

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:dbus, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Patch Publication Date: 12/23/2020

Vulnerability Publication Date: 12/23/2020

Reference Information

GLSA: 202012-17