Accepting request 56999 from Base:System

Accepted submit request 56999 from user dirkmueller

OBS-URL: https://build.opensuse.org/request/show/56999
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/dbus-1?expand=0&rev=59
This commit is contained in:
Berthold Gunreben 2011-01-05 14:49:02 +00:00 committed by Git OBS Bridge
commit 9760c8dcfe
7 changed files with 37 additions and 12 deletions

View File

@ -1,3 +1,16 @@
-------------------------------------------------------------------
Sun Jan 2 12:54:14 UTC 2011 - javier@opensuse.org
- Update to 1.4.1
+ Fix for CVE-2010-4352: sending messages with excessively-nested
variants can crash the bus. The existing restriction to 64-levels
of nesting previously only applied to the static type signature;
now it also applies to dynamic nesting using variants. Thanks to
Rémi Denis-Courmont for discoving this issue.
+ Various bug fixes.
+ For details, see
http://lists.freedesktop.org/archives/dbus/2010-December/013861.html
-------------------------------------------------------------------
Mon Nov 8 14:52:11 UTC 2010 - aj@suse.de

View File

@ -1,7 +1,7 @@
#
# spec file for package dbus-1-x11 (Version 1.4.0)
# spec file for package dbus-1-x11 (Version 1.4.1)
#
# Copyright (c) 2010 SUSE LINUX Products GmbH, Nuernberg, Germany.
# Copyright (c) 2011 SUSE LINUX Products GmbH, Nuernberg, Germany.
#
# All modifications and additions to the file contributed by third parties
# remain the property of their copyright owners, unless otherwise agreed
@ -17,7 +17,6 @@
# norootforbuild
Name: dbus-1-x11
BuildRequires: xorg-x11-devel
Url: http://dbus.freedesktop.org/
@ -28,7 +27,7 @@ Summary: D-Bus Message Bus System
# COMMON1-BEGIN
BuildRequires: doxygen libexpat-devel libzio pkgconfig
BuildRequires: audit-devel
Version: 1.4.0
Version: 1.4.1
Release: 4
AutoReqProv: on
# bug437293

View File

@ -1,7 +1,7 @@
#
# spec file for package dbus-1-x11 (Version 1.2.16)
# spec file for package dbus-1-x11 (Version 1.4.1)
#
# Copyright (c) 2009 SUSE LINUX Products GmbH, Nuernberg, Germany.
# Copyright (c) 2011 SUSE LINUX Products GmbH, Nuernberg, Germany.
#
# All modifications and additions to the file contributed by third parties
# remain the property of their copyright owners, unless otherwise agreed

View File

@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:27db28e3bd270e482c794e35c2a474c92383bfb4a7f3467a1cacd6ffe77f1988
size 1459728

3
dbus-1.4.1.tar.bz2 Normal file
View File

@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:957973032701c9a6625117f793513a0d8b1cd6a6bf35b5d775c762c05f1a4aec
size 1443101

View File

@ -1,3 +1,16 @@
-------------------------------------------------------------------
Sun Jan 2 12:54:14 UTC 2011 - javier@opensuse.org
- Update to 1.4.1
+ Fix for CVE-2010-4352: sending messages with excessively-nested
variants can crash the bus. The existing restriction to 64-levels
of nesting previously only applied to the static type signature;
now it also applies to dynamic nesting using variants. Thanks to
Rémi Denis-Courmont for discoving this issue.
+ Various bug fixes.
+ For details, see
http://lists.freedesktop.org/archives/dbus/2010-December/013861.html
-------------------------------------------------------------------
Mon Nov 8 14:52:11 UTC 2010 - aj@suse.de

View File

@ -1,7 +1,7 @@
#
# spec file for package dbus-1 (Version 1.4.0)
# spec file for package dbus-1 (Version 1.4.1)
#
# Copyright (c) 2010 SUSE LINUX Products GmbH, Nuernberg, Germany.
# Copyright (c) 2011 SUSE LINUX Products GmbH, Nuernberg, Germany.
#
# All modifications and additions to the file contributed by third parties
# remain the property of their copyright owners, unless otherwise agreed
@ -26,7 +26,7 @@ Summary: D-Bus Message Bus System
# COMMON1-BEGIN
BuildRequires: doxygen libexpat-devel libzio pkgconfig
BuildRequires: audit-devel
Version: 1.4.0
Version: 1.4.1
Release: 4
AutoReqProv: on
# bug437293