Regression in CVE-2012-3524 security update
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
dbus (Ubuntu) |
Fix Released
|
Low
|
Marc Deslauriers | ||
Hardy |
Fix Released
|
Low
|
Marc Deslauriers | ||
Lucid |
Fix Released
|
Low
|
Marc Deslauriers | ||
Natty |
Fix Released
|
Low
|
Marc Deslauriers | ||
Oneiric |
Fix Released
|
Low
|
Marc Deslauriers | ||
Precise |
Fix Released
|
Low
|
Marc Deslauriers | ||
Quantal |
Fix Released
|
Low
|
Marc Deslauriers |
Bug Description
There's a minor regression in CVE-2012-
Colin Walters and I put together a patch that works around this:
http://
It depends on a predecessor commit that just removes the DBUS_VERBOSE logic in the activation helper, since it's not useful.
This is in the D-Bus 1.6.8 release. Those two commits should be trivially backportable to older releases, though.
If you think this is serious enough to warrant an update, let me know if you want debdiffs for the current Ubuntu releases. We're working around this locally for now.
security vulnerability: | no → yes |
Changed in dbus (Ubuntu Hardy): | |
status: | New → Confirmed |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
importance: | Undecided → Low |
Changed in dbus (Ubuntu Lucid): | |
status: | New → Confirmed |
Changed in dbus (Ubuntu Natty): | |
status: | New → Confirmed |
Changed in dbus (Ubuntu Oneiric): | |
status: | New → Confirmed |
Changed in dbus (Ubuntu Quantal): | |
status: | New → Confirmed |
Changed in dbus (Ubuntu Lucid): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in dbus (Ubuntu Precise): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in dbus (Ubuntu Oneiric): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in dbus (Ubuntu Natty): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in dbus (Ubuntu Quantal): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in dbus (Ubuntu Precise): | |
status: | New → Confirmed |
Changed in dbus (Ubuntu Quantal): | |
importance: | Undecided → Low |
Changed in dbus (Ubuntu Precise): | |
importance: | Undecided → Low |
Changed in dbus (Ubuntu Oneiric): | |
importance: | Undecided → Low |
Changed in dbus (Ubuntu Natty): | |
importance: | Undecided → Low |
Changed in dbus (Ubuntu Lucid): | |
importance: | Undecided → Low |
This bug was fixed in the package dbus - 1.6.4-1ubuntu3
---------------
dbus (1.6.4-1ubuntu3) quantal-proposed; urgency=low
* REGRESSION FIX: some applications launched with the activation helper ADDRESS. (LP: #1058343) patches/ CVE-2012- 3524-regression -fix.patch: hardcode the libdbus- 1-3.postinst: trigger an upstart re-exec before
may need DBUS_STARTER_
- debian/
starter address to the default system bus address.
* Fix unclean shutdown after dbus upgrade (LP: #740390)
- debian/
shutdown or reboot so that it can safely unmount the root
filesystem.
-- Marc Deslauriers <email address hidden> Wed, 03 Oct 2012 07:14:40 -0400