-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 18 Jun 2009 06:12:34 +0200 Source: dbus Binary: dbus dbus-x11 libdbus-1-3 dbus-1-doc libdbus-1-dev Architecture: s390 Version: 1.2.1-5+lenny1 Distribution: stable-security Urgency: high Maintainer: s390 Build Daemon Changed-By: Michael Biebl Description: dbus - simple interprocess messaging system dbus-1-doc - simple interprocess messaging system (documentation) dbus-x11 - simple interprocess messaging system (X11 deps) libdbus-1-3 - simple interprocess messaging system libdbus-1-dev - simple interprocess messaging system (development headers) Closes: 532720 Changes: dbus (1.2.1-5+lenny1) stable-security; urgency=high . * debian/patches/52-CVE-2009-1189.patch - Security: The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834 Closes: #532720 Fixes: CVE-2009-1189 * Urgency high for the security fix. Checksums-Sha1: 47afa7d6e592a5de48662f73d43c7b00bf2a9f6f 286456 dbus_1.2.1-5+lenny1_s390.deb ed64ab92fe9c6765f33563d6158a9820e164a527 64984 dbus-x11_1.2.1-5+lenny1_s390.deb 967b8ebc11f1b6406942e5b26d9ec65eed72be23 166564 libdbus-1-3_1.2.1-5+lenny1_s390.deb e2ceab12b460ba585a90f6bc60fbf44980478787 258616 libdbus-1-dev_1.2.1-5+lenny1_s390.deb Checksums-Sha256: de7978e1345c74cd1e2d4260d23d866a2421362943497126e8f6fd4b0ee0c4f8 286456 dbus_1.2.1-5+lenny1_s390.deb bc7b04ccf2e677c3e1982b41ef029a971b8a8e1f50365619db5e633875b533f9 64984 dbus-x11_1.2.1-5+lenny1_s390.deb e7067597753fdf4823b41bef6353c7b10a8a4fec6603f1409a4495f3e266c43a 166564 libdbus-1-3_1.2.1-5+lenny1_s390.deb 2881bf594dec285cf95fdc217d693ebfb79bdfe153e3fbed81d464beb5e6df1c 258616 libdbus-1-dev_1.2.1-5+lenny1_s390.deb Files: 72d4f4bb1984f1dc84c0e116e14f118b 286456 devel optional dbus_1.2.1-5+lenny1_s390.deb 52c0501fc307e0dd30409a235ec490f3 64984 x11 optional dbus-x11_1.2.1-5+lenny1_s390.deb bfb102bf238071a310051323021d5454 166564 libs optional libdbus-1-3_1.2.1-5+lenny1_s390.deb 061303ce866ef9ac2a309db8a1d3b0fc 258616 libdevel optional libdbus-1-dev_1.2.1-5+lenny1_s390.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkqmiQ8ACgkQLkAIIn9ODhETOQCcCVDXOFISLKuBvnntteI2CXgJ 5+sAoIllq6dANXDgMH00FFFIdyMx0xJx =cFSj -----END PGP SIGNATURE-----