Re: [SECURITY] [DSA 1599-1] New dbus packages fix privilege escalation

View: New views
2 Messages — Rating Filter:   Alert me  

Re: [SECURITY] [DSA 1599-1] New dbus packages fix privilege escalation

by rossa :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Sehr geehrte Damen und Herren,

in der Zeit vom Montag, den 23.06.200 bis Freitag, den 27.06.2008 befinden wir uns im Urlaub.
 
Falls es während dieser Zeit zu Problemen mit unseren Servern kommen sollte, schreiben Sie bitte einen E-Mail an notfall@.... Unser Notdienst wird so schnell wie möglich reagieren und die Störung beseitigen. Wir bitten Sie dennoch um Verständnis dafür, dass dies während unseres Urlaubs, trotz aller Bemühungen, etwas länger als gewöhnlich dauern kann.

Geben Sie bitte immer den Namen des Servers, auf dem Sie gehostet sind (z.B. cyberwebserver-01.de), sowie den Namen des betroffenen Account (z.B. web1) an.

Wir danken Ihnen vielmals für Ihr Verständnis und freuen uns darauf Ihnen ab dem 30.06.2008 wieder frisch erholt zur Verfügung zu stehen.


Ihr Creatissimo Services - Team

--------------------------------------
Creatissimo Services
Pascal Rossa
Kantstr. 108
10627 Berlin

Tel: +49 30 - 39 93 03 63
Fax: +49 30 - 39 93 03 64
USt-IdNr.: DE247056918

mailto:info@...
http://www.creatissimo.net
--------------------------------------



--
To UNSUBSCRIBE, email to debian-security-REQUEST@...
with a subject of "unsubscribe". Trouble? Contact listmaster@...


Parent Message unknown Re: [SECURITY] [DSA 1599-1] New dbus packages fix privilege escalation

by Alexandra N. Kossovsky-3 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On Thu, Jun 26, 2008 at 11:06:06PM +0200, Moritz Muehlenhoff wrote:

> Package        : dbus
> Vulnerability  : programming error
> Problem type   : local
> Debian-specific: no
> CVE Id(s)      : CVE-2008-0595
>
> Havoc Pennington discovered that DBus, a simple interprocess messaging
> system, performs insufficient validation of security policies, which
> might allow local privilege escalation.
>
> We recommend that you upgrade your dbus packages.

As far as I can see, this update does not restart dbus daemon, so
vulnerable dbus process will run until reboot (or until manual restart
of dbus).  Have I missed anything?

----------
bash# aptitude upgrade
Reading package lists... Done
Building dependency tree... Done
Reading extended state information
Initializing package states... Done
Building tag database... Done
The following packages will be upgraded:
  dbus libdbus-1-3
2 packages upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
Need to get 620kB of archives. After unpacking 8192B will be used.
Do you want to continue? [Y/n/?]
Get:1 http://localhost etch/updates/main libdbus-1-3 1.0.2-1+etch1 [269kB]
Get:2 http://localhost etch/updates/main dbus 1.0.2-1+etch1 [351kB]
Fetched 620kB in 0s (2261kB/s)
(Reading database ... 141860 files and directories currently installed.)
Preparing to replace libdbus-1-3 1.0.2-1 (using .../libdbus-1-3_1.0.2-1+etch1_i386.deb) ...
Unpacking replacement libdbus-1-3 ...
Preparing to replace dbus 1.0.2-1 (using .../dbus_1.0.2-1+etch1_i386.deb) ...
Unpacking replacement dbus ...
Setting up libdbus-1-3 (1.0.2-1+etch1) ...

Setting up dbus (1.0.2-1+etch1) ...
Reloading system message bus config...done.
----------

Reloading != Restarting

Thank you for your work,
    Alexandra.

PS: CC me, I'm not subscribed to debian-security@
--
Alexandra N. Kossovsky
OKTET Labs (http://www.oktetlabs.ru/)
Phones: +7(921)956-42-86(mobile) +7(812)783-21-91(office)
e-mail: sasha@...


--
To UNSUBSCRIBE, email to debian-security-REQUEST@...
with a subject of "unsubscribe". Trouble? Contact listmaster@...

LightInTheBox - Buy quality products at wholesale price