OpenPKG Security Advisory
OpenPKG-SA-2006.041
Publisher Name: OpenPKG GmbH
Publisher Home: http://openpkg.com/
Advisory Id (public): OpenPKG-SA-2006.041
Advisory Type: OpenPKG Security Advisory (SA)
Advisory Directory: http://openpkg.com/go/OpenPKG-SA
Advisory Document: http://openpkg.com/go/OpenPKG-SA-2006.041
Advisory Published: 2008-10-06 22:58 UTC
Issue Id (internal): OpenPKG-SI-20061221.02
Issue First Created: 2006-12-21
Issue Last Modified: 2006-12-21
Issue Revision: 02
Subject Name: D-Bus
Subject Summary: message bus system
Subject Home: http://www.freedesktop.org/wiki/Software/dbus
Subject Versions: * < 1.0.2
Vulnerability Id: CVE-2006-6107
Vulnerability Scope: global (not OpenPKG specific)
Attack Feasibility: run-time
Attack Vector: local system
Attack Impact: denial of service
Description:
Kimmo Hämäläinen found [0] a vendor-confirmed Denial of Service
(DoS) vulnerability in the D-Bus [1] message bus system, versions
before 1.0.2. The flaw is in the "match_rule_equal" function in
"bus/signals.c" and allows local applications to remove match rules
for other applications and cause a DoS via lost process messages.
References:
[0] https://bugs.freedesktop.org/show_bug.cgi?id=9142
[1] http://www.freedesktop.org/wiki/Software/dbus
Primary Package Name: dbus
Primary Package Home: http://openpkg.org/go/package/dbus
Affected Distribution: Affected Branch: Affected Package:
OpenPKG Community 2-STABLE-20061018 dbus-0.93-2.20061018
OpenPKG Community 2-STABLE dbus-0.93-2.20061018
OpenPKG Community CURRENT dbus-1.0.1-20061118
Corrected Distribution: Corrected Branch: Corrected Package:
OpenPKG Community 2-STABLE-20061018 dbus-1.0.2-2.20061221
OpenPKG Community 2-STABLE dbus-1.0.2-2.20061221
OpenPKG Community CURRENT dbus-1.0.2-20061213