-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 18 Jun 2009 06:12:34 +0200 Source: dbus Binary: dbus dbus-x11 libdbus-1-3 dbus-1-doc libdbus-1-dev Architecture: mips Version: 1.2.1-5+lenny1 Distribution: stable-security Urgency: high Maintainer: Debian Build Daemon Changed-By: Michael Biebl Description: dbus - simple interprocess messaging system dbus-1-doc - simple interprocess messaging system (documentation) dbus-x11 - simple interprocess messaging system (X11 deps) libdbus-1-3 - simple interprocess messaging system libdbus-1-dev - simple interprocess messaging system (development headers) Closes: 532720 Changes: dbus (1.2.1-5+lenny1) stable-security; urgency=high . * debian/patches/52-CVE-2009-1189.patch - Security: The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834 Closes: #532720 Fixes: CVE-2009-1189 * Urgency high for the security fix. Checksums-Sha1: 941de1b4525ad2a8fb3490bb88b006580abb4138 247202 dbus_1.2.1-5+lenny1_mips.deb 5a2a7dfd39b4f1edee22053004fced6c833f5a19 64498 dbus-x11_1.2.1-5+lenny1_mips.deb 39c5648a9da56abc3b17eec6457d114fcfecdbdc 150832 libdbus-1-3_1.2.1-5+lenny1_mips.deb 463c2eb128c2c23258ab410e2779b583de28d0ca 257016 libdbus-1-dev_1.2.1-5+lenny1_mips.deb Checksums-Sha256: 836619b9506a71de0cb58940bcb3d55475da53e610b5d6f7ec95b1b73fecfaf2 247202 dbus_1.2.1-5+lenny1_mips.deb b4bb0f6731f677de9bf98d70646c7f995782db36f9c644ff5bb4109467b527ae 64498 dbus-x11_1.2.1-5+lenny1_mips.deb 695caf376eeb411a31bc17d2713b9f305be56ae6778d88e14d4428804e869248 150832 libdbus-1-3_1.2.1-5+lenny1_mips.deb 9b4e283387c9593b0eb5a7b38e9efb6e25de7cc3117b4b5af8c3baf2ccc7e7a4 257016 libdbus-1-dev_1.2.1-5+lenny1_mips.deb Files: c5b66959665d900dee20b069d205db0a 247202 devel optional dbus_1.2.1-5+lenny1_mips.deb 8f61fda7a3f7adf0e3069ad4535febf1 64498 x11 optional dbus-x11_1.2.1-5+lenny1_mips.deb c89353aaf1ff0acf40379b59c903153c 150832 libs optional libdbus-1-3_1.2.1-5+lenny1_mips.deb ca8b0fc29104a6483f2ce45346d3c2dd 257016 libdevel optional libdbus-1-dev_1.2.1-5+lenny1_mips.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQEcBAEBAgAGBQJKRgxeAAoJECIIoQCMVaAczboIAIpG6RHR0iQjEIKsKfBSonUb KsPWZEdEkumWm3Jie9/NccbAtUJv1RrkLGx1tIYzeqLt8oi4UlydLxhMVnuXAbtp TeC7dDfrHKp5Wo1rpS7ih2s1J+TWqW+KyEQFgRCNoDrmipAyO5zksrfdC6yG+ZWE A9Ji67v7oQWPtHjr16n9L9NX5oxKVlBkJ35yExGkHY12reOBQ4A+P7Gyfez/cdes 9wZfQKDp3DE5CR5l3XF6IFOgjqZQky6G4FCAOIXdcXjZg2MVGCfAFirCYqDjNS1Y kdLNpfJKD02Q+fFKkOblTsvH/coahexcUdXrvVt3dONe9oauExsm0Y/kOvJ2c2c= =KLXp -----END PGP SIGNATURE-----