diff options
author | Simon McVittie <smcv@debian.org> | 2014-06-30 15:15:50 +0100 |
---|---|---|
committer | Simon McVittie <smcv@debian.org> | 2014-06-30 15:15:50 +0100 |
commit | d35dfa78f7ee90bebc3c8a290a7f5877feb7eb8b (patch) | |
tree | 3ff7e7324aa42763ed8f76e7def35165b05aea76 /NEWS | |
parent | 2aa6558146965f91878fe7db131593a02736158e (diff) | |
download | dbus-d35dfa78f7ee90bebc3c8a290a7f5877feb7eb8b.tar.gz |
Imported Upstream version 1.8.6upstream/1.8.6
Diffstat (limited to 'NEWS')
-rw-r--r-- | NEWS | 24 |
1 files changed, 24 insertions, 0 deletions
@@ -1,3 +1,27 @@ +D-Bus 1.8.6 (2014-06-02) +== + +Security fixes: + +• On Linux ≥ 2.6.37-rc4, if sendmsg() fails with ETOOMANYREFS, silently drop + the message. This prevents an attack in which a malicious client can + make dbus-daemon disconnect a system service, which is a local + denial of service. + (fd.o #80163, CVE-2014-3532; Alban Crequy) + +• Track remaining Unix file descriptors correctly when more than one + message in quick succession contains fds. This prevents another attack + in which a malicious client can make dbus-daemon disconnect a system + service. + (fd.o #79694, fd.o #80469, CVE-2014-3533; Alejandro Martínez Suárez, + Simon McVittie, Alban Crequy) + +Other fixes: + +• When dbus-launch --exit-with-session starts a dbus-daemon but then cannot + attach to a session, kill the dbus-daemon as intended + (fd.o #74698, Роман Донченко) + D-Bus 1.8.4 (2014-06-10) == |