FlawAtlas
Search the atlas
SUSE-SU-2015:0457-1 Not scored

Security update for dbus-1

dbus-1 was updated to version 1.8.16 to fix one security issue. This update fixes the following security issue: - CVE-2015-0245: Do not allow non-uid-0 processes to send forged ActivationFailure messages. On Linux systems with systemd activation, this would allow a local denial of service (bnc#916343). These additional security hardenings are included: - Do not allow calls to UpdateActivationEnvironment from uids other than the uid of the dbus-daemon. If a system service installs unsafe security policy rules that allow arbitrary method calls (such as CVE-2014-8148) then this prevents memory consumption and possible privilege escalation via UpdateActivationEnvironment. - Do not allow calls to UpdateActivationEnvironment or the Stats interface on object paths other than /org/freedesktop/DBus. Some system services install unsafe security policy rules that allow arbitrary method calls to any destination, method and interface with a specified object path.

Exploit probability Not scored
Published March 4, 2015
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Desktop 12 dbus-1
SUSE:Linux Enterprise Desktop 12 dbus-1-x11
SUSE:Linux Enterprise Server 12 dbus-1
SUSE:Linux Enterprise Server 12 dbus-1-x11
SUSE:Linux Enterprise Server for SAP Applications 12 dbus-1
SUSE:Linux Enterprise Server for SAP Applications 12 dbus-1-x11
SUSE:Linux Enterprise Software Development Kit 12 dbus-1
SUSE:Linux Enterprise Software Development Kit 12 dbus-1-x11

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2015:0457-1

dbus-1 was updated to version 1.8.16 to fix one security issue. This update fixes the following security issue: - CVE-2015-0245: Do not allow non-uid-0 processes to send forged ActivationFailure messages. On Linux systems with systemd activation, this would allow a local denial of service (bnc#916343). These additional security hardenings are included: - Do not allow calls to UpdateActivationEnvironment from uids other than the uid of the dbus-daemon. If a system service installs unsafe security policy rules that allow arbitrary method calls (such as CVE-2014-8148) then this prevents memory consumption and possible privilege escalation via UpdateActivationEnvironment. - Do not allow calls to UpdateActivationEnvironment or the Stats interface on object paths other than /org/freedesktop/DBus. Some system services install unsafe security policy rules that allow arbitrary method calls to any destination, method and interface with a specified object path.

View original source

05 / REFERENCES

Further evidence