Hide Forgot
A flaw was reported in D-Bus's file descriptor passing feature. A local attacker could use this flaw to cause an invalid file descriptor to be forwarded to a service or application, causing it to disconnect from the bus, typically resulting in that service or application exiting. It is reported that versions 1.3.0 and newer are affected. Acknowledgements: Red Hat would like to thank D-Bus upstream for reporting this issue.
This is now public: http://openwall.com/lists/oss-security/2014/07/02/4
Created dbus tracking bugs for this issue: Affects: fedora-all [bug 1115636]
Created mingw-dbus tracking bugs for this issue: Affects: fedora-all [bug 1115637] Affects: epel-7 [bug 1115638]
dbus-1.6.12-9.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
Upstream commit: http://cgit.freedesktop.org/dbus/dbus/commit/?id=07f4c12efe3b9bd45d109bc5fbaf6d9dbf69d78e