USN-4398-2: DBus vulnerability
USN-4398-1 fixed a vulnerability in DBus. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: Kevin Backhouse discovered that DBus incorrectly handled file descriptors. A local attacker could possibly use this issue to cause DBus to crash, resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this DBus vulnerability?
The vulnerability ID for this DBus vulnerability is USN-4398-2.
What software versions are affected by this vulnerability?
Ubuntu 12.04 ESM (libdbus-1-3 version 1.4.18-1ubuntu1.10) and Ubuntu 14.04 ESM (libdbus-1-3 version 1.6.18-0ubuntu4.5+esm2) are affected by this vulnerability.
What is the severity of this vulnerability?
The severity of this vulnerability is not specified in the information provided.
How can I fix this vulnerability?
To fix this vulnerability, update libdbus-1-3 to the specified versions: 1.4.18-1ubuntu1.10 for Ubuntu 12.04 ESM and 1.6.18-0ubuntu4.5+esm2 for Ubuntu 14.04 ESM.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found on the Ubuntu Security Notices website at https://ubuntu.com/security/notices/USN-4398-1 and the Canonical website at https://ubuntu.com/security/CVE-2020-12049.