-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 18 Jun 2009 06:12:34 +0200 Source: dbus Binary: dbus dbus-x11 libdbus-1-3 dbus-1-doc libdbus-1-dev Architecture: mipsel Version: 1.2.1-5+lenny1 Distribution: stable-security Urgency: high Maintainer: Debian Build Daemon Changed-By: Michael Biebl Description: dbus - simple interprocess messaging system dbus-1-doc - simple interprocess messaging system (documentation) dbus-x11 - simple interprocess messaging system (X11 deps) libdbus-1-3 - simple interprocess messaging system libdbus-1-dev - simple interprocess messaging system (development headers) Closes: 532720 Changes: dbus (1.2.1-5+lenny1) stable-security; urgency=high . * debian/patches/52-CVE-2009-1189.patch - Security: The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834 Closes: #532720 Fixes: CVE-2009-1189 * Urgency high for the security fix. Checksums-Sha1: 1501e1435b0128ba913e2364eb16a13716b99403 246102 dbus_1.2.1-5+lenny1_mipsel.deb 1e68998663c106d0e66ea6a4157b3c02bee5a55d 64528 dbus-x11_1.2.1-5+lenny1_mipsel.deb 56443407772f009ef9e09ca93f00759199621498 150130 libdbus-1-3_1.2.1-5+lenny1_mipsel.deb 6acade6711b56f528df3074eb59b095db20b197e 256382 libdbus-1-dev_1.2.1-5+lenny1_mipsel.deb Checksums-Sha256: 204fa1b868e4fc3b8eca7e6b72438112d9ec05612dd4f20a291a35e3fc3c7505 246102 dbus_1.2.1-5+lenny1_mipsel.deb 59b2e787eb2522357e724c8470aa6a308236e8aacde4da3a4243fca29676a942 64528 dbus-x11_1.2.1-5+lenny1_mipsel.deb b66b9b5aace9facf2a3ddc152866a19e3bf161021c9895e6d99f01692bbc7083 150130 libdbus-1-3_1.2.1-5+lenny1_mipsel.deb 44c2ab6474829b7501d6eff717abd779b49895a90285ed7f7357fca430e01c73 256382 libdbus-1-dev_1.2.1-5+lenny1_mipsel.deb Files: 38f40717cb0f202e99067a484ce80848 246102 devel optional dbus_1.2.1-5+lenny1_mipsel.deb e82065ecb4221b024d0fa0f7716b3a4a 64528 x11 optional dbus-x11_1.2.1-5+lenny1_mipsel.deb 5658d2cdf77ad75b314f781f9630a8e3 150130 libs optional libdbus-1-3_1.2.1-5+lenny1_mipsel.deb 7a3757146955ab439ca286aa9fc6dd94 256382 libdevel optional libdbus-1-dev_1.2.1-5+lenny1_mipsel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQEcBAEBAgAGBQJKRgxeAAoJECIIoQCMVaAc9qYIAJKMBGjJdi/JaHCxYpfhP+pe VZer9M8AsD2fldZDFXTIJV96oEdHa4z56iVR+ZlWT5oaOjJ7c92SN2OHIYiJNoUO BE3YqeXxskMtsZDEhcCnKXzrVjPiCAMioTqwMcversqPEViSY2yq0VSYZbul50Iz lJ4RGagyac+Gn7fGC/ZsA95dfSFnUpS/OCZgllH2LtGsyht/rWQHyQ9vgBoSh9lL Fkn5jBNwF5fJfwzS0kg2aiKtBYK71yl44h36nCvUTHNEKO9b3WlqNfyreKjWXvm5 o/PJEW+c+VexaQ2RumuoFBUUHvVXtyjsksCA8Imi1SF7YAlYvbBpUDCTJDHGYko= =Inwk -----END PGP SIGNATURE-----