[MacPorts] #46504: Update: dbus 1.8.14
MacPorts
noreply at macports.org
Fri Feb 13 06:18:41 PST 2015
#46504: Update: dbus 1.8.14
-----------------------------+------------------------
Reporter: mschamschula@… | Owner: mcalhoun@…
Type: update | Status: new
Priority: Normal | Milestone:
Component: ports | Version: 2.3.3
Resolution: | Keywords: haspatch
Port: dbus |
-----------------------------+------------------------
Comment (by mschamschula@…):
In the meantime dbus has been updated to version 1.8.16:
{{{
The “poorly concealed wrestlers” release.
Security fixes:
• Do not allow non-uid-0 processes to send forged ActivationFailure
messages. On Linux systems with systemd activation, this would
allow a local denial of service: unprivileged processes could
flood the bus with these forged messages, winning the race with
the actual service activation and causing an error reply
to be sent back when service auto-activation was requested.
This does not prevent the real service from being started,
so it only works while the real service is not running.
(CVE-2015-0245, fd.o #88811; Simon McVittie)
}}}
--
Ticket URL: <https://trac.macports.org/ticket/46504#comment:2>
MacPorts <https://www.macports.org/>
Ports system for OS X
More information about the macports-tickets
mailing list