-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Tue, 21 Oct 2008 10:25:43 +0000 Source: dbus Binary: dbus-1-doc libdbus-1-dev libdbus-1-3 dbus dbus-1-utils Architecture: source all i386 Version: 1.0.2-1+etch2 Distribution: stable-security Urgency: high Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org> Changed-By: Steffen Joeris <white@debian.org> Description: dbus - simple interprocess messaging system dbus-1-doc - simple interprocess messaging system (documentation) dbus-1-utils - simple interprocess messaging system (utilities) libdbus-1-3 - simple interprocess messaging system libdbus-1-dev - simple interprocess messaging system (development headers) Closes: 501443 Changes: dbus (1.0.2-1+etch2) stable-security; urgency=high . * Non-maintainer upload by the security team * The dbus_signature_validate function does not validate properly, which could be used to perform a DoS (Closes: #501443) Fixes: CVE-2008-3834 Files: 476bb3df500c50f67b4088317482e0ef 824 devel optional dbus_1.0.2-1+etch2.dsc 27df2fd0bc5cb93069d6c10d89e0214a 19909 devel optional dbus_1.0.2-1+etch2.diff.gz 68e4e1787515928f95af670ec2677663 1623126 doc optional dbus-1-doc_1.0.2-1+etch2_all.deb cfa20eea1e6e8be195d520199e8415c6 349844 devel optional dbus_1.0.2-1+etch2_i386.deb ebf1993ab8d40f4d10becd43324c3fb7 269032 libs optional libdbus-1-3_1.0.2-1+etch2_i386.deb 98c8270b762a20bffc194124562c2a68 184284 utils optional dbus-1-utils_1.0.2-1+etch2_i386.deb 116b0084af4713242092e2b07a64734f 335874 libdevel optional libdbus-1-dev_1.0.2-1+etch2_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkj9t8sACgkQ62zWxYk/rQdFVACcCAdNfJeB+vAT6vyHFXNcxX3+ tlwAoL5t1EEXce7Z/s0jl43aq53UzFLp =q7OK -----END PGP SIGNATURE----- Accepted: dbus-1-doc_1.0.2-1+etch2_all.deb to pool/main/d/dbus/dbus-1-doc_1.0.2-1+etch2_all.deb dbus-1-utils_1.0.2-1+etch2_i386.deb to pool/main/d/dbus/dbus-1-utils_1.0.2-1+etch2_i386.deb dbus_1.0.2-1+etch2.diff.gz to pool/main/d/dbus/dbus_1.0.2-1+etch2.diff.gz dbus_1.0.2-1+etch2.dsc to pool/main/d/dbus/dbus_1.0.2-1+etch2.dsc dbus_1.0.2-1+etch2_i386.deb to pool/main/d/dbus/dbus_1.0.2-1+etch2_i386.deb libdbus-1-3_1.0.2-1+etch2_i386.deb to pool/main/d/dbus/libdbus-1-3_1.0.2-1+etch2_i386.deb libdbus-1-dev_1.0.2-1+etch2_i386.deb to pool/main/d/dbus/libdbus-1-dev_1.0.2-1+etch2_i386.deb