Important CentOS dbus-glib Update

Metadata

high
7.2
dbus-glib-0.73-11.el5_9.i386.rpm, dbus-glib-0.73-11.el5_9.src.rpm, dbus-glib-0.73-11.el5_9.x86_64.rpm, dbus-glib-0.86-6.el6.i686.rpm, dbus-glib-0.86-6.el6.src.rpm, dbus-glib-0.86-6.el6.x86_64.rpm, dbus-glib-devel-0.73-11.el5_9.i386.rpm, dbus-glib-devel-0.73-11.el5_9.x86_64.rpm, dbus-glib-devel-0.86-6.el6.i686.rpm, dbus-glib-devel-0.86-6.el6.x86_64.rpm
CVE-2013-0292
rhn.redhat.com, lists.centos.org, lists.centos.org, lists.centos.org
2013-03-01
2017-07-27 19:05
CVE-2013-0292 dbus-glib
CVE-2013-0292
2017-04-01 19:06
2017-01-05 20:10

Description


Updated dbus-glib packages that fix one security issue are now available
for Red Hat Enterprise Linux 5 and 6.

The Red Hat Security Response Team has rated this update as having
important security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from the
CVE link in the References section.

dbus-glib is an add-on library to integrate the standard D-Bus library with
the GLib main loop and threading model.

A flaw was found in the way dbus-glib filtered the message sender (message
source subject) when the "NameOwnerChanged" signal was received. This
could trick a system service using dbus-glib (such as fprintd) into
believing a signal was sent from a privileged process, when it was not. A
local attacker could use this flaw to escalate their privileges.
(CVE-2013-0292)

All dbus-glib users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
linked against dbus-glib, such as fprintd and NetworkManager, must be
restarted for this update to take effect.
Please see https://www.redhat.com/footer/terms-of-use.html

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
5 dbus-glib dbus-glib-0.73-11.el5_9.i386.rpm
dbus-glib dbus-glib-0.73-11.el5_9.src.rpm
dbus-glib dbus-glib-0.73-11.el5_9.x86_64.rpm
dbus-glib-devel dbus-glib-devel-0.73-11.el5_9.i386.rpm
dbus-glib-devel dbus-glib-devel-0.73-11.el5_9.x86_64.rpm
6 dbus-glib dbus-glib-0.86-6.el6.i686.rpm
dbus-glib dbus-glib-0.86-6.el6.src.rpm
dbus-glib dbus-glib-0.86-6.el6.x86_64.rpm
dbus-glib-devel dbus-glib-devel-0.86-6.el6.i686.rpm
dbus-glib-devel dbus-glib-devel-0.86-6.el6.x86_64.rpm