[sisyphus] [gmane.comp.freedesktop.dbus] SECURITY: CAN-2005-0201 - D-Bus 0.36.2 released
Anton Farygin
=?iso-8859-1?q?rider_=CE=C1_altlinux=2Ecom?=
Вт Авг 30 17:02:47 MSD 2005
Соответственно сегодня dbus-0.36.2
отправляется в Sisyphus и в 3.0-branch, всем рекомендуется обновить.
Rgds,
Rider
On Mon, 29 Aug 2005 16:32:59 -0400, John (J5) Palmieri wrote:
> D-Bus 0.36.2 is released. This is a security release that fixes an
> exploit allowing one user to attach to another user's session bus.
>
> It should be noted that in order to exploit this issue, another user must
> be running dbus on the target machine, and the user has to guess the
> correct session bus address, which is not trivial.
>
> Anyone using the 0.3x D-Bus series should upgrade.
>
> relevant bug:
> https://bugs.freedesktop.org/show_bug.cgi?id=2436
>
> This issue is already public as CAN-2005-0201
>
> As usual:
> http://dbus.freedesktop.org/releases/dbus-0.36.2.tar.gz
Подробная информация о списке рассылки Sisyphus