CVE-2009-1189
Published: 27 April 2009
The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.
Priority
Status
Package | Release | Status |
---|---|---|
dbus Launchpad, Ubuntu, Debian |
upstream |
Released
(1.2.14)
|
dapper |
Released
(0.60-6ubuntu8.4)
|
|
hardy |
Released
(1.1.20-1ubuntu3.3)
|
|
intrepid |
Released
(1.2.4-0ubuntu1.1)
|
|
jaunty |
Released
(1.2.12-0ubuntu2.1)
|
|
Patches: upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=e8f8c1c5a2bddfbf43c168323c9c9fd78f51a643 |