Vulnerability Bulletins

DSA-3099 dbus - security update

   
Affected software Debian
 
Simon McVittie discovered that the fix forCVE-2014-3636 was incorrect, as it did not fully address the underlyingdenial-of-service vector. This update starts the D-Bus daemon as rootinitially, so that it can properly raise its file descriptor count.

More info:

https://www.debian.org/security/2014/dsa-3099