~racb/ubuntu/+source/dbus:lpusip/ubuntu/saucy-security

Last commit made on 2014-07-08
Get this branch:
git clone -b lpusip/ubuntu/saucy-security https://git.launchpad.net/~racb/ubuntu/+source/dbus
Only Robie Basak can upload to this branch. If you are Robie Basak please log in for upload directions.

Branch merges

Branch information

Name:
lpusip/ubuntu/saucy-security
Repository:
lp:~racb/ubuntu/+source/dbus

Recent commits

389345a... by Marc Deslauriers

Import patches-unapplied version 1.6.12-0ubuntu10.1 to ubuntu/saucy-security

Imported using usd-importer.

Publish parent: 2d9c102e122e2b8bc7f5ac86d14f0e44cd075eda

New changelog entries:
  * SECURITY UPDATE: denial of service via activation errors
    - debian/patches/CVE-2014-3477.patch: improve error handling in
      bus/activation.*, bus/services.c.
    - CVE-2014-3477
  * SECURITY UPDATE: denial of service via ETOOMANYREFS
    - debian/patches/CVE-2014-3532.patch: drop message on ETOOMANYREFS in
      dbus/dbus-sysdeps.*, dbus/dbus-transport-socket.c.
    - CVE-2014-3532
  * SECURITY UPDATE: denial of service via invalid file descriptor
    - debian/patches/CVE-2014-3533.patch: fix memory handling in
      dbus/dbus-message.c.
    - CVE-2014-3533

2d9c102... by Tyler Hicks

Import patches-unapplied version 1.6.12-0ubuntu10 to ubuntu/saucy

Imported using usd-importer.

Publish parent: 306e5e55e5877694e4f7f60012b83daa70033498
Changelog parent: e3702b2f2d8caba07b38ee3d499d1cda92fc0996

e3702b2... by Tyler Hicks

Import patches-unapplied version 1.6.12-0ubuntu10 to ubuntu/saucy-proposed

Imported using usd-importer.

Publish parent: e9acf6d6d020af2972a196d9bc71c684ff884e27

New changelog entries:
  * debian/patches/aa-mediation.patch: Attempt to open() the mask file in
    apparmorfs/features/dbus rather than simply stat() the dbus directory.
    This is an important difference because AppArmor does not mediate the
    stat() syscall. This resulted in problems in an environment where
    dbus-daemon, running inside of an LXC container, did not have the
    necessary AppArmor rules to access apparmorfs but the stat() succeeded
    so mediation was not properly disabled. (LP: #1238267)
    This problem was exposed after dropping aa-kernel-compat-check.patch
    because the compat check was an additional check that performed a test
    query. The test query was failing in the above scenario, which did result
    in mediation being disabled.
  * debian/patches/aa-get-connection-apparmor-security-context.patch,
    debian/patches/aa-mediate-eavesdropping.patch: Refresh these patches to
    accomodate the above change

306e5e5... by Tyler Hicks

Import patches-unapplied version 1.6.12-0ubuntu9 to ubuntu/saucy

Imported using usd-importer.

Publish parent: f6fdee0893d2ca85e5fad682aa782bcc0100f7bb
Changelog parent: e9acf6d6d020af2972a196d9bc71c684ff884e27

e9acf6d... by Tyler Hicks

Import patches-unapplied version 1.6.12-0ubuntu9 to ubuntu/saucy-proposed

Imported using usd-importer.

Publish parent: 6af1ee34d34eeba00e70f4e5b4e78cebf0435867

New changelog entries:
  * debian/patches/aa-mediate-eavesdropping.patch: Fix a regression that
    caused dbus-daemon to segfault when AppArmor mediation is disabled, or
    unsupported by the kernel, and an application attempts to eavesdrop
    (LP: #1237059)

f6fdee0... by Tyler Hicks

Import patches-unapplied version 1.6.12-0ubuntu8 to ubuntu/saucy

Imported using usd-importer.

Publish parent: 56d52d46f5a0b75d0767872e456265a91c303e4d
Changelog parent: 6af1ee34d34eeba00e70f4e5b4e78cebf0435867

6af1ee3... by Tyler Hicks

Import patches-unapplied version 1.6.12-0ubuntu8 to ubuntu/saucy-proposed

Imported using usd-importer.

Publish parent: c7d4c1f6ec64023cb7207d6d0bb4f6db683d09bb

New changelog entries:
  * debian/patches/aa-kernel-compat-check.patch: Drop this patch. It was a
    temporary compatibility check to paper over incompatibilities between
    dbus-daemon, libapparmor, and the AppArmor kernel code while AppArmor
    D-Bus mediation was in development.
  * debian/patches/aa-mediation.patch: Fix a bug that resulted in all actions
    denied by AppArmor to be audited. Auditing such actions is the default,
    but it should be possible to quiet audit messages by using the "deny"
    AppArmor rule modifier. (LP: #1226356)
  * debian/patches/aa-mediation.patch: Fix a bug in the code that builds
    AppArmor queries for the process that is receiving a message. The
    message's destination was being used, as opposed to the message's source,
    as the peer name in the query string. (LP: #1233895)
  * debian/patches/aa-mediate-eavesdropping.patch: Don't allow applications
    that are confined by AppArmor to eavesdrop. Ideally, this would be
    configurable with AppArmor policy, but the parser does not yet support
    any type of eavesdropping permission. For now, confined applications will
    simply not be allowed to eavesdrop. (LP: #1229280)

56d52d4... by Dimitri John Ledkov

Import patches-unapplied version 1.6.12-0ubuntu7 to ubuntu/saucy

Imported using usd-importer.

Publish parent: eeba724bce581dd9a31773340aa37ad4a7510ee7
Changelog parent: c7d4c1f6ec64023cb7207d6d0bb4f6db683d09bb

c7d4c1f... by Dimitri John Ledkov

Import patches-unapplied version 1.6.12-0ubuntu7 to ubuntu/saucy-proposed

Imported using usd-importer.

Publish parent: 63e774493e3265a387193018d96c3637dab9f11b

New changelog entries:
  * Enable log output in session dbus upstart job.

eeba724... by Dimitri John Ledkov

Import patches-unapplied version 1.6.12-0ubuntu6 to ubuntu/saucy

Imported using usd-importer.

Publish parent: f72c61610b5b7634d2d5ff02fc8cf7302d3f65aa
Changelog parent: 63e774493e3265a387193018d96c3637dab9f11b