[MacPorts] #46504: Update: dbus 1.8.14

MacPorts noreply at macports.org
Fri Feb 13 06:18:41 PST 2015


#46504: Update: dbus 1.8.14
-----------------------------+------------------------
  Reporter:  mschamschula@…  |      Owner:  mcalhoun@…
      Type:  update          |     Status:  new
  Priority:  Normal          |  Milestone:
 Component:  ports           |    Version:  2.3.3
Resolution:                  |   Keywords:  haspatch
      Port:  dbus            |
-----------------------------+------------------------

Comment (by mschamschula@…):

 In the meantime dbus has been updated to version 1.8.16:
 {{{
 The “poorly concealed wrestlers” release.

 Security fixes:

 • Do not allow non-uid-0 processes to send forged ActivationFailure
   messages. On Linux systems with systemd activation, this would
   allow a local denial of service: unprivileged processes could
   flood the bus with these forged messages, winning the race with
   the actual service activation and causing an error reply
   to be sent back when service auto-activation was requested.
   This does not prevent the real service from being started,
   so it only works while the real service is not running.
   (CVE-2015-0245, fd.o #88811; Simon McVittie)
 }}}

-- 
Ticket URL: <https://trac.macports.org/ticket/46504#comment:2>
MacPorts <https://www.macports.org/>
Ports system for OS X


More information about the macports-tickets mailing list