安全公告详情

NS-SA-2020-0016

2020-03-04 10:24:28

简介

important: dbus/sudo security update

严重级别

important

主题

An update for dbus/sudo is now available for NewStart CGSL MAIN 4.05.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

dbus: D-BUS is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility.
sudo: This package provides debug information for package sudo. Debug information is useful when developing applications that use this package or when debugging this package.


Security Fix(es):
dbus: before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing authentication bypass.(CVE-2019-12749)
dbus: bugfix
sudo: A flaw was found in the way sudo implemented running commands with arbitrary user ID. If a sudoers entry is written to allow the attacker to run a command as any user except root, this flaw can be used by the attacker to bypass that restriction.(CVE-2019-14287)
sudo: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 4.05.F17.

影响组件

  • dbus
  • sudo

影响产品

  • CGSL MAIN 4.05

更新包

{"fix":[{"product":"CGSL MAIN 4.05","pkgs":[{"binary":["dbus-1.2.24-11.el6_10.x86_64.rpm","dbus-debuginfo-1.2.24-11.el6_10.x86_64.rpm","dbus-devel-1.2.24-11.el6_10.x86_64.rpm","dbus-doc-1.2.24-11.el6_10.noarch.rpm","dbus-libs-1.2.24-11.el6_10.x86_64.rpm","dbus-x11-1.2.24-11.el6_10.x86_64.rpm"],"source":"dbus-1.2.24-11.el6_10.src.rpm"},{"binary":["sudo-debuginfo-1.8.6p3-29.el6_10.2.x86_64.rpm","sudo-devel-1.8.6p3-29.el6_10.2.x86_64.rpm","sudo-1.8.6p3-29.el6_10.2.x86_64.rpm"],"source":"sudo-1.8.6p3-29.el6_10.2.src.rpm"}]}]}

CVE

参考