Path to this page:
Subject: CVS commit: pkgsrc/sysutils/dbus
From: Thomas Klausner
Date: 2014-07-06 16:54:32
Message id: 20140706145432.7D61E96@cvs.netbsd.org
Log Message:
Update to 1.8.6:
D-Bus 1.8.6 (2014-06-02)
==
Security fixes:
⢠On Linux ⥠2.6.37-rc4, if sendmsg() fails with ETOOMANYREFS, \
silently drop
the message. This prevents an attack in which a malicious client can
make dbus-daemon disconnect a system service, which is a local
denial of service.
(fd.o #80163, CVE-2014-3532; Alban Crequy)
⢠Track remaining Unix file descriptors correctly when more than one
message in quick succession contains fds. This prevents another attack
in which a malicious client can make dbus-daemon disconnect a system
service.
(fd.o #79694, fd.o #80469, CVE-2014-3533; Alejandro MartÃnez Suárez,
Simon McVittie, Alban Crequy)
Other fixes:
⢠When dbus-launch --exit-with-session starts a dbus-daemon but then cannot
attach to a session, kill the dbus-daemon as intended
(fd.o #74698, Роман ÐонÑенко)
Files: