========================================================================== Ubuntu Security Notice USN-1753-1 February 27, 2013 dbus-glib vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 10.04 LTS Summary: An attacker could send crafted input to applications using DBus-GLib and possibly escalate privileges. Software Description: - dbus-glib: simple interprocess messaging system Details: Sebastian Krahmer and Bastien Nocera discovered that DBus-GLib did not properly validate the message sender when the "NameOwnerChanged" signal was received. A local attacker could possibly use this issue to escalate their privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: libdbus-glib-1-2 0.100-1ubuntu0.1 Ubuntu 12.04 LTS: libdbus-glib-1-2 0.98-1ubuntu1.1 Ubuntu 11.10: libdbus-glib-1-2 0.94-4ubuntu0.1 Ubuntu 10.04 LTS: libdbus-glib-1-2 0.84-1ubuntu0.3 After a standard system update you need to reboot your computer to make all the necessary changes. References: http://www.ubuntu.com/usn/usn-1753-1 CVE-2013-0292 Package Information: https://launchpad.net/ubuntu/+source/dbus-glib/0.100-1ubuntu0.1 https://launchpad.net/ubuntu/+source/dbus-glib/0.98-1ubuntu1.1 https://launchpad.net/ubuntu/+source/dbus-glib/0.94-4ubuntu0.1 https://launchpad.net/ubuntu/+source/dbus-glib/0.84-1ubuntu0.3
Spotlight

Information security executives need to be strategic thinkers
Posted on 17 June 2013. | George Baker, the Director of Information Security at Exostar, talks about the challenges in working in a dynamic threat landscape, offers tips for aspiring infosec leaders, and more.

Large orgs in denial about own security breaches?
Posted on 14 June 2013. | Over two thirds (66%) of large organizations said they either had not experienced a security incident in the last 12-18 months or were unsure if they had.

Vulnerability scanning with PureCloud
Posted on 12 June 2013. | nCircle PureCloud is a cloud-based network security scanning product built upon the companies' vulnerability and risk management system IP360.

To hack back or not to hack back?
Posted on 12 June 2013. | If you think of cyberspace as a new resource for you and your organization, it makes sense to protect your part of it as best you can. But is it a good idea?

Reactions from the security community to the NSA spying scandal
Posted on 11 June 2013. | Read on for comments on this scandal that Help Net Security received from a variety of security professionals and analysts.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.


