[ubuntu/xenial-security] dbus 1.10.6-1ubuntu3.6 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Tue Jun 16 17:00:35 UTC 2020
dbus (1.10.6-1ubuntu3.6) xenial-security; urgency=medium
* SECURITY UPDATE: DoS via file descriptor leak
- debian/patches/CVE-2020-12049-1.patch: on MSG_CTRUNC, close the fds
we did receive in dbus/dbus-sysdeps-unix.c.
- debian/patches/CVE-2020-12049-2.patch: assert that we don't leak file
descriptors in test/fdpass.c.
- CVE-2020-12049
dbus (1.10.6-1ubuntu3.5) xenial; urgency=medium
* Prevent logind from leaking session files (LP: #1846787). Fixed by
upstream patches:
- d/p/Only-read-one-message-at-a-time-if-there-are-fds-pen.patch
- d/p/bus-Fix-timeout-restarts.patch
- d/p/DBusMainLoop-ensure-all-required-timeouts-are-restar.patch
Date: 2020-06-11 20:02:13.746113+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/dbus/1.10.6-1ubuntu3.6
-------------- next part --------------
Sorry, changesfile not available.
More information about the Xenial-changes
mailing list