{"id":"MGASA-2020-0262","summary":"Updated dbus packages fix security vulnerability","details":"The updated packages fix a security vulnerability:\nAn issue was discovered in dbus \u003e= 1.3.0 before 1.12.18. The DBusServer\nin libdbus, as used in dbus-daemon, leaks file descriptors when a message\nexceeds the per-message file descriptor limit. A local attacker with\naccess to the D-Bus system bus or another system service's private\nAF_UNIX socket could use this to make the system service reach its file\ndescriptor limit, denying service to subsequent D-Bus clients. \n(CVE-2020-12049)\n","modified":"2026-04-16T04:43:43.378618017Z","published":"2020-06-15T07:54:40Z","upstream":["CVE-2020-12049"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0262.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=26735"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2020/06/04/3"},{"type":"WEB","url":"https://www.debian.org/lts/security/2020/dla-2235"}],"affected":[{"package":{"name":"dbus","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/dbus?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.13.8-4.2.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0262.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}