Bug#510744: system-tools-backends: /etc/dbus-1/system.d file needs alterations for fd.o #18961

Simon McVittie smcv at debian.org
Sun Jan 4 19:43:37 UTC 2009


# blocker for #503532 (CVE-2008-4311)
severity 510744 serious
block 503532 by 510744
user pkg-utopia-maintainers at lists.alioth.debian.org
usertags 510744 + CVE-2008-4311
thanks

Actually, this is RC, as it blocks the fix for #503532. During normal
operation, processes in system-tools-backends call Introspect on each other,
which is no longer allowed:

Jan  4 18:37:29 replica dbus-daemon: Rejected send message, 1 matched rules; type="method_call", sender=":1.2" (uid=0 pid=14213 comm="/usr/bin/system-tools-backends ") interface="org.freedesktop.DBus.Introspectable" member="Introspect" error name="(unset)" requested_reply=0 destination="org.freedesktop.SystemToolsBackends.Platform" (uid=0 pid=14701 comm="/usr/bin/perl /usr/share//system-tools-backends-2."))
 
I'm looking into it.

    Simon
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 155 bytes
Desc: Digital signature
Url : http://lists.alioth.debian.org/pipermail/pkg-gnome-maintainers/attachments/20090104/82b6cf44/attachment.pgp 


More information about the pkg-gnome-maintainers mailing list