MGASA-2013-0057
Date: | February 17th, 2013 |
Affected releases: | 2 |
Media: | Core |
Description:
Updated dbus-glib packages fix security vulnerability:
A privilege escalation flaw was found in the way dbus-glib, the D-Bus
add-on library to integrate the standard D-Bus library with the GLib
thread abstraction and main loop, performed filtering of the message
sender (message source subject), when the NameOwnerChanged signal was
received. A local attacker could use this flaw to escalate their
privileges (CVE-2013-0292).
Updated Packages:
i586:
libdbus-glib-0.96-1.1.mga2.i586.rpm
libdbus-glib1_2-0.96-1.1.mga2.i586.rpm
dbus-glib-debug-0.96-1.1.mga2.i586.rpm
x86_64:
lib64dbus-glib-0.96-1.1.mga2.x86_64.rpm
lib64dbus-glib1_2-0.96-1.1.mga2.x86_64.rpm
dbus-glib-debug-0.96-1.1.mga2.x86_64.rpm
SRPMS:
dbus-glib-0.96-1.1.mga2.src.rpm
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0292
https://bugzilla.redhat.com/show_bug.cgi?id=911658
https://bugs.mageia.org/show_bug.cgi?id=9087