pkgsrc/sysutils/dbus
wiz 8ea13be8fa Update to 1.8.14:
D-Bus 1.8.14 (2015-01-05)
==

The “40lb of roofing nails” release.

Security hardening:

• Do not allow calls to UpdateActivationEnvironment from uids other than
  the uid of the dbus-daemon. If a system service installs unsafe
  security policy rules that allow arbitrary method calls
  (such as CVE-2014-8148) then this prevents memory consumption and
  possible privilege escalation via UpdateActivationEnvironment.

  We believe that in practice, privilege escalation here is avoided
  by dbus-daemon-launch-helper sanitizing its environment; but
  it seems better to be safe.

• Do not allow calls to UpdateActivationEnvironment or the Stats interface
  on object paths other than /org/freedesktop/DBus. Some system services
  install unsafe security policy rules that allow arbitrary method calls
  to any destination, method and interface with a specified object path;
  while less bad than allowing arbitrary method calls, these security
  policies are still harmful, since dbus-daemon normally offers the
  same API on all object paths and other system services might behave
  similarly.

Other fixes:

• Add missing initialization so GetExtendedTcpTable doesn't crash on
  Windows Vista SP0 (fd.o #77008, Илья А. Ткаченко)
2015-01-05 23:25:20 +00:00
..
files Add smf support and solaris-specific console_user verification 2014-09-13 09:47:11 +00:00
patches Add smf support and solaris-specific console_user verification 2014-09-13 09:47:11 +00:00
buildlink3.mk Restrict lib/dbus-1.0/include/dbus/dbus-arch-deps.h buildlink 2014-01-29 13:01:53 +00:00
DEINSTALL
DESCR
distinfo Update to 1.8.14: 2015-01-05 23:25:20 +00:00
hacks.mk
INSTALL
Makefile Update to 1.8.14: 2015-01-05 23:25:20 +00:00
MESSAGE make this less embarrassing: "fedora core" is no longer a thing. 2014-12-02 05:20:24 +00:00
options.mk Darwin supports kqueue(2), too. 2012-09-02 13:02:13 +00:00
PLIST Update to 1.8.0: 2014-04-03 09:09:06 +00:00