Vulnerability Bulletins

DSA-3161 dbus - security update

   
Affected software Debian
 
Simon McVittie discovered a local denial of service flaw in dbus, anasynchronous inter-process communication system. On systems withsystemd-style service activation, dbus-daemon does not prevent forgedActivationFailure messages from non-root processes. A malicious localuser could use this flaw to trick dbus-daemon into thinking that systemdfailed to activate a system service, resulting in an error reply back tothe requester.

More info:

https://www.debian.org/security/2015/dsa-3161