Announcing D-Bus 1.10.14

Simon McVittie simon.mcvittie at collabora.co.uk
Tue Nov 29 00:42:56 UTC 2016


The “Well, other bands know more than three chords” release.

http://dbus.freedesktop.org/releases/dbus/dbus-1.10.14.tar.gz
http://dbus.freedesktop.org/releases/dbus/dbus-1.10.14.tar.gz.asc
git tag: dbus-1.10.14

Fixes:

• Work around an undesired effect of the fix for CVE-2014-3637
  (fd.o #80559), in which processes that frequently send fds, such as
  logind during a flood of new PAM sessions, can get disconnected for
  continuously having at least one fd "in flight" for too long;
  dbus-daemon interprets that as a potential denial of service attack.
  The workaround is to disable that check for uid 0 process such as
  logind, with a message in the system log. The bug remains open while
  we look for a more general solution.
  (fd.o #95263, LP#1591411; Simon McVittie)

• Don't run the test test-dbus-launch-x11.sh if X11 autolaunching
  was disabled at compile time. That test is not expected to work
  in that configuration. (fd.o #98665, Simon McVittie)

-- 
Simon McVittie, Collabora Ltd
on behalf of the D-Bus maintainers
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 878 bytes
Desc: This is a digitally signed message part
URL: <https://lists.freedesktop.org/archives/dbus/attachments/20161129/a49d8f19/attachment.sig>


More information about the dbus mailing list