CVE-2015-0245
Publication date 13 February 2015
Last updated 24 July 2024
Ubuntu priority
D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before systemd responds.
Status
Package | Ubuntu Release | Status |
---|---|---|
dbus | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 1.6.18-0ubuntu4.4
|
|
Notes
seth-arnold
The policy change is recommended for stable use, though the code-based changes were made for platforms where uid==0 may not be omnipotent -- we should probably use both in our packages, or at least both for the versions with distro-patched AppArmor support.
Patch details
Package | Patch details |
---|---|
dbus |
References
Related Ubuntu Security Notices (USN)
- USN-3116-1
- DBus vulnerabilities
- 1 November 2016