{
  "Definition": [
    {
      "ID": "oval:org.altlinux.errata:def:20193127",
      "Version": "oval:org.altlinux.errata:def:20193127",
      "Class": "patch",
      "Metadata": {
        "Title": "ALT-PU-2019-3127: package `dbus` update to version 1.12.16-alt2",
        "AffectedList": [
          {
            "Family": "unix",
            "Platforms": [
              "ALT Linux branch p9"
            ],
            "Products": [
              "ALT Server",
              "ALT Virtualization Server",
              "ALT Workstation",
              "ALT Workstation K",
              "ALT Education",
              "Simply Linux",
              "Starterkit"
            ]
          }
        ],
        "References": [
          {
            "RefID": "ALT-PU-2019-3127",
            "RefURL": "https://errata.altlinux.org/ALT-PU-2019-3127",
            "Source": "ALTPU"
          },
          {
            "RefID": "BDU:2019-03326",
            "RefURL": "https://bdu.fstec.ru/vul/2019-03326",
            "Source": "BDU"
          },
          {
            "RefID": "CVE-2019-12749",
            "RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-12749",
            "Source": "CVE"
          }
        ],
        "Description": "This update upgrades dbus to version 1.12.16-alt2. \nSecurity Fix(es):\n\n * BDU:2019-03326: Уязвимость функции DBUS_COOKIE_SHA1 библиотеки libdbus системы межпроцессорного взаимодействия D-Bus, позволяющая нарушителю нарушить целостность данных или получить несанкционированный доступ к защищаемой информации\n\n * CVE-2019-12749: dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing authentication bypass.\n\n * #37461: dbus-1.12.16-alt1 causes dbus restart during the package update",
        "Advisory": {
          "From": "errata.altlinux.org",
          "Severity": "High",
          "Rights": "Copyright 2023 BaseALT Ltd.",
          "Issued": {
            "Date": "2019-11-13"
          },
          "Updated": {
            "Date": "2019-11-13"
          },
          "bdu": [
            {
              "Cvss": "AV:L/AC:L/Au:N/C:P/I:P/A:N",
              "Cvss3": "AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "Cwe": "CWE-287",
              "Href": "https://bdu.fstec.ru/vul/2019-03326",
              "Impact": "High",
              "Public": "20190528",
              "CveID": "BDU:2019-03326"
            }
          ],
          "Cves": [
            {
              "Cvss": "AV:L/AC:L/Au:N/C:P/I:P/A:N",
              "Cvss3": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "Cwe": "CWE-59",
              "Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-12749",
              "Impact": "High",
              "Public": "20190611",
              "CveID": "CVE-2019-12749"
            }
          ],
          "Bugzilla": [
            {
              "Id": "37461",
              "Href": "https://bugzilla.altlinux.org/37461",
              "Data": "dbus-1.12.16-alt1 causes dbus restart during the package update"
            }
          ],
          "AffectedCpeList": {
            "Cpe": [
              "cpe:/o:alt:kworkstation:9",
              "cpe:/o:alt:workstation:9",
              "cpe:/o:alt:server:9",
              "cpe:/o:alt:server-v:9",
              "cpe:/o:alt:education:9",
              "cpe:/o:alt:slinux:9",
              "cpe:/o:alt:starterkit:p9",
              "cpe:/o:alt:kworkstation:9.1",
              "cpe:/o:alt:workstation:9.1",
              "cpe:/o:alt:server:9.1",
              "cpe:/o:alt:server-v:9.1",
              "cpe:/o:alt:education:9.1",
              "cpe:/o:alt:slinux:9.1",
              "cpe:/o:alt:starterkit:9.1",
              "cpe:/o:alt:kworkstation:9.2",
              "cpe:/o:alt:workstation:9.2",
              "cpe:/o:alt:server:9.2",
              "cpe:/o:alt:server-v:9.2",
              "cpe:/o:alt:education:9.2",
              "cpe:/o:alt:slinux:9.2",
              "cpe:/o:alt:starterkit:9.2"
            ]
          }
        }
      },
      "Criteria": {
        "Operator": "AND",
        "Criterions": [
          {
            "TestRef": "oval:org.altlinux.errata:tst:1001",
            "Comment": "ALT Linux must be installed"
          }
        ],
        "Criterias": [
          {
            "Operator": "OR",
            "Criterions": [
              {
                "TestRef": "oval:org.altlinux.errata:tst:20193127001",
                "Comment": "dbus is earlier than 0:1.12.16-alt2"
              },
              {
                "TestRef": "oval:org.altlinux.errata:tst:20193127002",
                "Comment": "dbus-tools is earlier than 0:1.12.16-alt2"
              },
              {
                "TestRef": "oval:org.altlinux.errata:tst:20193127003",
                "Comment": "dbus-tools-gui is earlier than 0:1.12.16-alt2"
              },
              {
                "TestRef": "oval:org.altlinux.errata:tst:20193127004",
                "Comment": "libdbus is earlier than 0:1.12.16-alt2"
              },
              {
                "TestRef": "oval:org.altlinux.errata:tst:20193127005",
                "Comment": "libdbus-devel is earlier than 0:1.12.16-alt2"
              }
            ]
          }
        ]
      }
    }
  ]
}