[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253741

 
 

909

 
 

197391

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SA:2009:013 -- SUSE dbus-1, hal, NetworkManager, PackageKit, ... local privilege escalation

ID: oval:org.secpod.oval:def:400083Date: (C)2012-01-31   (M)2021-09-12
Class: PATCHFamily: unix




Joachim Breitner discovered that the default DBus system policy was too permissive. In fact the default policy was to allow all calls on the bus. Many services expected that the default was to deny everything and therefore only installed rules that explicitly allow certain calls with the result that intended access control for some services was not applied. The updated DBus package now installs a new policy that denies access by default. Unfortunately some DBus services actually relied on the insecure default setting and break with the new policy. Therefore quite a number of packages is affected by this DBus update. The updated DBus daemon now logs access violations via syslog. If you see log entries about rejected messages of type &qt method_call &qt during normal operation the application that caused it likely needs an updated DBus policy. Please contact the application vendor in this case.

Platform:
openSUSE 10.3
openSUSE 11.1
openSUSE 11.0
Product:
dbus-1
hal
NetworkManager
PackageKit
Reference:
SUSE-SA:2009:013
CVE-2008-4311
CVE-2009-0365
CVE-2009-0578
CVE    3
CVE-2008-4311
CVE-2009-0365
CVE-2009-0578
CPE    3
cpe:/o:opensuse:opensuse:11.1
cpe:/o:opensuse:opensuse:11.0
cpe:/o:opensuse:opensuse:10.3

© SecPod Technologies