~racb/ubuntu/+source/dbus:lpusip/applied/debian/lenny

Last commit made on 2011-10-01
Get this branch:
git clone -b lpusip/applied/debian/lenny https://git.launchpad.net/~racb/ubuntu/+source/dbus
Only Robie Basak can upload to this branch. If you are Robie Basak please log in for upload directions.

Branch merges

Branch information

Name:
lpusip/applied/debian/lenny
Repository:
lp:~racb/ubuntu/+source/dbus

Recent commits

5bc3f5d... by Nico Golde <email address hidden>

Import patches-applied version 1.2.1-5+lenny2 to applied/debian/lenny

Imported using usd-importer.

Publish parent: 5f4f2a7b9f34fca5271fc5f8d43629f9e2e766d8
Unapplied parent: bdd951c27cb0e289e437aa9898118c1302dbc7cf

New changelog entries:
  * Non-maintainer upload by the Security Team.
  * Backport upstream patch to fix a possible call stack overflow and thus
    denial of service, when processing messages with excessive nested variants.
    This fix restricts the nesting level to 64 (52-CVE-2010-4352.patch).

bdd951c... by Nico Golde <email address hidden>

Import patches-unapplied version 1.2.1-5+lenny2 to debian/lenny

Imported using usd-importer.

Publish parent: edd1d03691a4ccf4dda7edbbe4f9c8d4b4583a79

New changelog entries:
  * Non-maintainer upload by the Security Team.
  * Backport upstream patch to fix a possible call stack overflow and thus
    denial of service, when processing messages with excessive nested variants.
    This fix restricts the nesting level to 64 (52-CVE-2010-4352.patch).

5f4f2a7... by Michael Biebl

Import patches-applied version 1.2.1-5+lenny1 to applied/debian/lenny

Imported using usd-importer.

Publish parent: 91463f5aa76ac1e5d88b75170967fa1868614e4b
Unapplied parent: edd1d03691a4ccf4dda7edbbe4f9c8d4b4583a79

New changelog entries:
  * debian/patches/52-CVE-2009-1189.patch
    - Security: The _dbus_validate_signature_with_reason function
      (dbus-marshal-validate.c) uses incorrect logic to validate a basic type,
      which allows remote attackers to spoof a signature via a crafted key.
      NOTE: this is due to an incorrect fix for CVE-2008-3834
      Closes: #532720
      Fixes: CVE-2009-1189
  * Urgency high for the security fix.

edd1d03... by Michael Biebl

Import patches-unapplied version 1.2.1-5+lenny1 to debian/lenny

Imported using usd-importer.

Publish parent: 5c0a9eb65547dacd427fefcfc2ffa5473d8cd6c2

New changelog entries:
  * debian/patches/52-CVE-2009-1189.patch
    - Security: The _dbus_validate_signature_with_reason function
      (dbus-marshal-validate.c) uses incorrect logic to validate a basic type,
      which allows remote attackers to spoof a signature via a crafted key.
      NOTE: this is due to an incorrect fix for CVE-2008-3834
      Closes: #532720
      Fixes: CVE-2009-1189
  * Urgency high for the security fix.

91463f5... by Simon McVittie

Import patches-applied version 1.2.1-5 to applied/debian/lenny

Imported using usd-importer.

Publish parent: 9a16c6ed3329dbd0c54ef902406c42aed18a5bcf
Changelog parent: b54d6df2e6e8c38b267cb4473cdb0eed417d50bc
Unapplied parent: ddb265fad1d31f3bad48342f8e1dcca5096e26ea

5c0a9eb... by Simon McVittie

Import patches-unapplied version 1.2.1-5 to debian/lenny

Imported using usd-importer.

Publish parent: 91d19570b5c0dd3647cb340a75a5dbcb36d0d6f8
Changelog parent: ddb265fad1d31f3bad48342f8e1dcca5096e26ea

b54d6df... by Simon McVittie

Import patches-applied version 1.2.1-5 to applied/debian/sid

Imported using usd-importer.

Publish parent: 964a6993a708192753b71ce4182c9b22c1e836e4
Unapplied parent: ddb265fad1d31f3bad48342f8e1dcca5096e26ea

New changelog entries:
  [ Sjoerd Simons ]
  * debian/patches/CVE-2008-4311.patch:
    + Added, Fixes CVE-2008-4311. A mistake in the default configuration for
      the system bus (system.conf) which made the default policy for both sent
      and received messages effectively *allow*, and not deny as intended. This
      patch fixes the send side permissions (Closes: #503532, #508032)
  * Urgency high for the security fix
  [ Simon McVittie ]
  * Rename CVE-*.patch to prefix them with a sequence number so it's clear
    what order they should apply in
  * Add 51-CVE-2008-4311-but-allow-signals.patch, cherry-picked from upstream
    git commit d899734475: after fixing CVE-2008-4311, re-allow emitting
    signals
  * debian/patches/3[0-4]*.patch, cherry-picked from upstream git (see patches
    for commit IDs): add logging when permission to send a message is denied
  * debian/patches/35-syslog-h.patch: #include <syslog.h> to fix compilation
    with the logging patches applied
  * Add myself to Uploaders

ddb265f... by Simon McVittie

Import patches-unapplied version 1.2.1-5 to debian/sid

Imported using usd-importer.

Publish parent: 834ae7949dc9169f236a411b9fff91b018aa9ef4

New changelog entries:
  [ Sjoerd Simons ]
  * debian/patches/CVE-2008-4311.patch:
    + Added, Fixes CVE-2008-4311. A mistake in the default configuration for
      the system bus (system.conf) which made the default policy for both sent
      and received messages effectively *allow*, and not deny as intended. This
      patch fixes the send side permissions (Closes: #503532, #508032)
  * Urgency high for the security fix
  [ Simon McVittie ]
  * Rename CVE-*.patch to prefix them with a sequence number so it's clear
    what order they should apply in
  * Add 51-CVE-2008-4311-but-allow-signals.patch, cherry-picked from upstream
    git commit d899734475: after fixing CVE-2008-4311, re-allow emitting
    signals
  * debian/patches/3[0-4]*.patch, cherry-picked from upstream git (see patches
    for commit IDs): add logging when permission to send a message is denied
  * debian/patches/35-syslog-h.patch: #include <syslog.h> to fix compilation
    with the logging patches applied
  * Add myself to Uploaders

9a16c6e... by Michael Biebl

Import patches-applied version 1.2.1-4 to applied/debian/lenny

Imported using usd-importer.

Publish parent: 19dd3fe91c6bed2daa0a4c354c05093be4788cc4
Changelog parent: 964a6993a708192753b71ce4182c9b22c1e836e4
Unapplied parent: 834ae7949dc9169f236a411b9fff91b018aa9ef4

91d1957... by Michael Biebl

Import patches-unapplied version 1.2.1-4 to debian/lenny

Imported using usd-importer.

Publish parent: a3c7a9f45f269dab038cab8c48caa0a7ac4ce933
Changelog parent: 834ae7949dc9169f236a411b9fff91b018aa9ef4