PublicDateAtUSN: 2015-02-13 Candidate: CVE-2015-0245 PublicDate: 2015-02-13 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0245 http://www.openwall.com/lists/oss-security/2015/02/09/6 https://ubuntu.com/security/notices/USN-3116-1 Description: D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before systemd responds. Ubuntu-Description: Notes: seth-arnold> The policy change is recommended for stable use, though the code-based changes were made for platforms where uid==0 may not be omnipotent -- we should probably use both in our packages, or at least both for the versions with distro-patched AppArmor support. Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=777545 Priority: medium Discovered-by: Simon McVittie Assigned-to: mdeslaur CVSS: Patches_dbus: upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=6dbd09fedc396c53b25ea73c6c8a278beca349c7 (via policy) upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=aaea59916398d1c590490edb0471a01bcf20e6d7 (via code, p1) upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=03c5e161752fe1ff4925955800ca9c78d09a6e0c (via code, p2) upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.8&id=6dbd09fedc396c53b25ea73c6c8a278beca349c7 (1.8) upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.6&id=f9697e04f1c9871cb54a99f087e97e4bb9e41e06 (1.6) upstream_dbus: released (1.8.16-1) lucid_dbus: not-affected precise_dbus: released (1.4.18-1ubuntu1.8) precise/esm_dbus: released (1.4.18-1ubuntu1.8) trusty_dbus: released (1.6.18-0ubuntu4.4) trusty/esm_dbus: released (1.6.18-0ubuntu4.4) utopic_dbus: ignored (reached end-of-life) vivid_dbus: ignored (reached end-of-life) vivid/stable-phone-overlay_dbus: ignored (reached end-of-life) vivid/ubuntu-core_dbus: ignored (reached end-of-life) wily_dbus: not-affected (1.10.0-1ubuntu1) xenial_dbus: not-affected (1.10.6-1ubuntu3) esm-infra/xenial_dbus: not-affected (1.10.6-1ubuntu3) yakkety_dbus: not-affected (1.10.6-1ubuntu3) zesty_dbus: not-affected (1.10.6-1ubuntu3) devel_dbus: not-affected (1.10.6-1ubuntu3)