ALAS2023-2023-213


Amazon Linux 2023 Security Advisory: ALAS-2023-213
Advisory Release Date: 2023-06-21 19:10 Pacific
Advisory Updated Date: 2023-06-27 20:58 Pacific
Severity: Medium

Issue Overview:

D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6. (CVE-2023-34969)


Affected Packages:

dbus


Issue Correction:
Run dnf update dbus --releasever 2023.1.20230628 to update your system.

New Packages:
aarch64:
    dbus-libs-debuginfo-1.12.28-1.amzn2023.0.1.aarch64
    dbus-debugsource-1.12.28-1.amzn2023.0.1.aarch64
    dbus-devel-1.12.28-1.amzn2023.0.1.aarch64
    dbus-x11-1.12.28-1.amzn2023.0.1.aarch64
    dbus-tests-debuginfo-1.12.28-1.amzn2023.0.1.aarch64
    dbus-libs-1.12.28-1.amzn2023.0.1.aarch64
    dbus-debuginfo-1.12.28-1.amzn2023.0.1.aarch64
    dbus-daemon-1.12.28-1.amzn2023.0.1.aarch64
    dbus-daemon-debuginfo-1.12.28-1.amzn2023.0.1.aarch64
    dbus-tools-debuginfo-1.12.28-1.amzn2023.0.1.aarch64
    dbus-1.12.28-1.amzn2023.0.1.aarch64
    dbus-x11-debuginfo-1.12.28-1.amzn2023.0.1.aarch64
    dbus-tests-1.12.28-1.amzn2023.0.1.aarch64
    dbus-tools-1.12.28-1.amzn2023.0.1.aarch64

noarch:
    dbus-common-1.12.28-1.amzn2023.0.1.noarch
    dbus-doc-1.12.28-1.amzn2023.0.1.noarch

src:
    dbus-1.12.28-1.amzn2023.0.1.src

x86_64:
    dbus-debuginfo-1.12.28-1.amzn2023.0.1.x86_64
    dbus-x11-debuginfo-1.12.28-1.amzn2023.0.1.x86_64
    dbus-tools-debuginfo-1.12.28-1.amzn2023.0.1.x86_64
    dbus-libs-debuginfo-1.12.28-1.amzn2023.0.1.x86_64
    dbus-tools-1.12.28-1.amzn2023.0.1.x86_64
    dbus-libs-1.12.28-1.amzn2023.0.1.x86_64
    dbus-x11-1.12.28-1.amzn2023.0.1.x86_64
    dbus-1.12.28-1.amzn2023.0.1.x86_64
    dbus-devel-1.12.28-1.amzn2023.0.1.x86_64
    dbus-tests-debuginfo-1.12.28-1.amzn2023.0.1.x86_64
    dbus-daemon-debuginfo-1.12.28-1.amzn2023.0.1.x86_64
    dbus-debugsource-1.12.28-1.amzn2023.0.1.x86_64
    dbus-daemon-1.12.28-1.amzn2023.0.1.x86_64
    dbus-tests-1.12.28-1.amzn2023.0.1.x86_64