Announcing D-Bus 1.10.14
Simon McVittie
simon.mcvittie at collabora.co.uk
Tue Nov 29 00:42:56 UTC 2016
The “Well, other bands know more than three chords” release.
http://dbus.freedesktop.org/releases/dbus/dbus-1.10.14.tar.gz
http://dbus.freedesktop.org/releases/dbus/dbus-1.10.14.tar.gz.asc
git tag: dbus-1.10.14
Fixes:
• Work around an undesired effect of the fix for CVE-2014-3637
(fd.o #80559), in which processes that frequently send fds, such as
logind during a flood of new PAM sessions, can get disconnected for
continuously having at least one fd "in flight" for too long;
dbus-daemon interprets that as a potential denial of service attack.
The workaround is to disable that check for uid 0 process such as
logind, with a message in the system log. The bug remains open while
we look for a more general solution.
(fd.o #95263, LP#1591411; Simon McVittie)
• Don't run the test test-dbus-launch-x11.sh if X11 autolaunching
was disabled at compile time. That test is not expected to work
in that configuration. (fd.o #98665, Simon McVittie)
--
Simon McVittie, Collabora Ltd
on behalf of the D-Bus maintainers
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 878 bytes
Desc: This is a digitally signed message part
URL: <https://lists.freedesktop.org/archives/dbus/attachments/20161129/a49d8f19/attachment.sig>
More information about the dbus
mailing list