openSUSE Security Update: Security update for dbus-1 ______________________________________________________________________________
Announcement ID: openSUSE-SU-2014:1454-1 Rating: moderate References: Cross-References: CVE-2014-7824 Affected Products: openSUSE 12.3 ______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
dbus-1 was updated to version 1.6.26 to fix one security issue and several other issues.
This security issue was fixed: - Increase dbus-daemon's RLIMIT_NOFILE rlimit to 65536 to stop an attacker from exhausting the system bus' file descriptors (CVE-2014-7824).
Patch Instructions:
To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product:
- openSUSE 12.3:
zypper in -t patch openSUSE-2014-691
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.3 (i586 x86_64):
dbus-1-1.6.26-2.30.1 dbus-1-debuginfo-1.6.26-2.30.1 dbus-1-debugsource-1.6.26-2.30.1 dbus-1-devel-1.6.26-2.30.1 dbus-1-x11-1.6.26-2.30.1 dbus-1-x11-debuginfo-1.6.26-2.30.1 dbus-1-x11-debugsource-1.6.26-2.30.1 libdbus-1-3-1.6.26-2.30.1 libdbus-1-3-debuginfo-1.6.26-2.30.1
- openSUSE 12.3 (x86_64):
dbus-1-32bit-1.6.26-2.30.1 dbus-1-debuginfo-32bit-1.6.26-2.30.1 dbus-1-devel-32bit-1.6.26-2.30.1 libdbus-1-3-32bit-1.6.26-2.30.1 libdbus-1-3-debuginfo-32bit-1.6.26-2.30.1
- openSUSE 12.3 (noarch):
dbus-1-devel-doc-1.6.26-2.30.1
References: