Oval Definition:
oval:org.mitre.oval:def:7908
Revision Date
:
2014-06-23
Version
:
18
Title
:
DSA-1837 dbus -- programming error
Description
:
It was discovered that the dbus_signature_validate function in dbus, a simple interprocess messaging system, is prone to a denial of service attack. This issue was caused by an incorrect fix for DSA-1658-1.
Family
:
unix
Class
:
patch
Status
:
ACCEPTED
Reference(s)
:
CVE-2009-1189
DSA-1837
Platform(s)
:
Debian GNU/Linux 4.0
Debian GNU/Linux 5.0
Product(s)
:
dbus
Definition Synopsis
Release section
Debian GNU/Linux 5.0 is installed
AND
Architecture section
Architecture independent section
Installed architecture is all
AND
dbus-1-doc is earlier than 1.2.1-5+lenny1
OR
Architecture dependent section
Supported architectures section
Installed architecture is amd64
OR
Installed architecture is sparc
OR
Installed architecture is arm
OR
Installed architecture is i386
OR
Installed architecture is armel
OR
Installed architecture is mips
OR
Installed architecture is ia64
OR
Installed architecture is alpha
OR
Installed architecture is powerpc
OR
Installed architecture is mipsel
OR
Installed architecture is hppa
AND
Packages section
libdbus-1-3 is earlier than 1.2.1-5+lenny1
OR
dbus-x11 is earlier than 1.2.1-5+lenny1
OR
dbus is earlier than 1.2.1-5+lenny1
OR
libdbus-1-dev is earlier than 1.2.1-5+lenny1
OR
Release section
Debian GNU/Linux 4.0 is installed.
AND
Architecture section
Architecture independent section
Installed architecture is all
AND
dbus-1-doc is earlier than 1.0.2-1+etch3
OR
Architecture dependent section
Supported architectures section
Installed architecture is amd64
OR
Installed architecture is sparc
OR
Installed architecture is arm
OR
Installed architecture is i386
OR
Installed architecture is mips
OR
Installed architecture is alpha
OR
Installed architecture is powerpc
OR
Installed architecture is mipsel
OR
Installed architecture is hppa
AND
Packages section
dbus-1-utils is earlier than 1.0.2-1+etch3
OR
libdbus-1-3 is earlier than 1.0.2-1+etch3
OR
dbus is earlier than 1.0.2-1+etch3
OR
libdbus-1-dev is earlier than 1.0.2-1+etch3
BACK