[Pkg-utopia-maintainers] Bug#512228: Bug#512228: Bug#512228: dbus-daemon error message in auth.log

Michael Biebl biebl at debian.org
Mon Feb 16 12:42:53 UTC 2009


reassign 512228 system-tools-backends
thanks

Andrew Deason wrote:
> I see this too, but it seems like a bug in system-tools-backends to me.
> I first started seeing this message when s-t-b was fixed due to
> CVE-2008-4311, so I think the dbus system.d config just isn't right.

Agreed. reassigning to system-tools-backends.

> There's an explicit <deny
> send_destination="org.freedesktop.SystemToolsBackends"/> in there,
> which is specifically what e.g. nautilus is calling.
> 
> If I add <allow send_destination="org.freedesktop.SystemToolsBackends"
> send_interface="org.freedesktop.SystemToolsBackends" send_member="get"
> send_type="method_call"/> to the default policy
> in /etc/dbus-1/system.d/system-tools-backends.conf, it looks like I
> don't get the message anymore. Is this a correct fix?

Depends on how s-t-b works. Usually such an interface should be limited to a
specific user/group or by at_console.

If s-t-b is using PolicyKit internally to authorise the method calls, then it
can open up it's dbus interface to everyone.

Cheers,
Michael


-- 
Why is it that all of the instruments seeking intelligent life in the
universe are pointed away from Earth?

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 260 bytes
Desc: OpenPGP digital signature
Url : http://lists.alioth.debian.org/pipermail/pkg-utopia-maintainers/attachments/20090216/3c8d99b9/attachment.pgp 


More information about the Pkg-utopia-maintainers mailing list