Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.60458
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDVSA-2008:054 (dbus)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to dbus
announced via advisory MDVSA-2008:054.

A vulnerability was discovered by Havoc Pennington in how the
dbus-daemon applied its security policy. A user with the ability
to connect to the dbus-daemon could possibly execute certain method
calls that they should not normally have access to.

The updated packages have been patched to correct these issues.

Users will have to reboot the system once these packages have been
installed in order to prevent problems due to service dependencies
on the messagebus service.

Affected: 2007.0, 2007.1, 2008.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2008:054

Risk factor : Medium

CVSS Score:
4.6

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-0595
BugTraq ID: 28023
http://www.securityfocus.com/bid/28023
Bugtraq: 20080307 rPSA-2008-0099-1 dbus dbus-glib dbus-qt dbus-x11 (Google Search)
http://www.securityfocus.com/archive/1/489280/100/0/threaded
Debian Security Information: DSA-1599 (Google Search)
http://www.debian.org/security/2008/dsa-1599
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00893.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00911.html
http://www.mandriva.com/security/advisories?name=MDVSA-2008:054
http://lists.freedesktop.org/archives/dbus/2008-February/009401.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9353
http://www.redhat.com/support/errata/RHSA-2008-0159.html
http://securitytracker.com/id?1019512
http://secunia.com/advisories/29148
http://secunia.com/advisories/29160
http://secunia.com/advisories/29171
http://secunia.com/advisories/29173
http://secunia.com/advisories/29281
http://secunia.com/advisories/29323
http://secunia.com/advisories/30869
http://secunia.com/advisories/32281
SuSE Security Announcement: SUSE-SR:2008:006 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html
SuSE Security Announcement: openSUSE-SU-2012:1418 (Google Search)
http://lists.opensuse.org/opensuse-updates/2012-10/msg00094.html
http://www.ubuntu.com/usn/usn-653-1
http://www.vupen.com/english/advisories/2008/0694
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.