* New upstream bug fix release: (LP: #279425)
- Fix crash on dbus_signature_validate("a{(ii)i}", NULL), which would
unexpectedly abort the calling program. [CVE-2008-3834]
- Close file descriptors before exec()ing helpers, to avoid locking
hardware like video cards by eternally open file fds. (LP: #230877)
- A small number of compilation and portability fixes.
-- Martin Pitt <email address hidden> Tue, 07 Oct 2008 15:26:32 +0200
This bug was fixed in the package dbus - 1.2.4-0ubuntu1
---------------
dbus (1.2.4-0ubuntu1) intrepid; urgency=low
* New upstream bug fix release: (LP: #279425) validate( "a{(ii) i}", NULL), which would
- Fix crash on dbus_signature_
unexpectedly abort the calling program. [CVE-2008-3834]
- Close file descriptors before exec()ing helpers, to avoid locking
hardware like video cards by eternally open file fds. (LP: #230877)
- A small number of compilation and portability fixes.
-- Martin Pitt <email address hidden> Tue, 07 Oct 2008 15:26:32 +0200