-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 18 Jun 2009 06:12:34 +0200 Source: dbus Binary: dbus dbus-x11 libdbus-1-3 dbus-1-doc libdbus-1-dev Architecture: powerpc Version: 1.2.1-5+lenny1 Distribution: stable-security Urgency: high Maintainer: powerpc Build Daemon (praetorius) Changed-By: Michael Biebl Description: dbus - simple interprocess messaging system dbus-1-doc - simple interprocess messaging system (documentation) dbus-x11 - simple interprocess messaging system (X11 deps) libdbus-1-3 - simple interprocess messaging system libdbus-1-dev - simple interprocess messaging system (development headers) Closes: 532720 Changes: dbus (1.2.1-5+lenny1) stable-security; urgency=high . * debian/patches/52-CVE-2009-1189.patch - Security: The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834 Closes: #532720 Fixes: CVE-2009-1189 * Urgency high for the security fix. Checksums-Sha1: 0e8203ad74f4da832f38ef1c2e7415f66c0bf5ad 252104 dbus_1.2.1-5+lenny1_powerpc.deb 32f3e4a765ea4617f7b239f669831c84cb2da097 67286 dbus-x11_1.2.1-5+lenny1_powerpc.deb b32bdb279978940f84a156b23b5263d458cf9af9 157156 libdbus-1-3_1.2.1-5+lenny1_powerpc.deb d4a065ba43bda2486f5317cbd0b23a42bb95b532 243468 libdbus-1-dev_1.2.1-5+lenny1_powerpc.deb Checksums-Sha256: 2bb8fde18386e3ade6f872ff36b1cc05d4bbfdfdec1f3d39915746468242a9f1 252104 dbus_1.2.1-5+lenny1_powerpc.deb 5a61cedd54c31b8eac03f093452a0ec29dc98d7e59575e9cb3e5d5902d6d9f74 67286 dbus-x11_1.2.1-5+lenny1_powerpc.deb f1414dc7004a6c3ca940d87f557844da57292c2fbcd09e2494d498f043410b10 157156 libdbus-1-3_1.2.1-5+lenny1_powerpc.deb fca654ff90d317b25e51208733375d6e8179120845501908220b75a6d04a22ff 243468 libdbus-1-dev_1.2.1-5+lenny1_powerpc.deb Files: af29662c0e472962196a03d9bcac0624 252104 devel optional dbus_1.2.1-5+lenny1_powerpc.deb 5d871cb882a468fc0d21981024b7bd5e 67286 x11 optional dbus-x11_1.2.1-5+lenny1_powerpc.deb 8ce5392e803ce8b824865362c5e7ceaf 157156 libs optional libdbus-1-3_1.2.1-5+lenny1_powerpc.deb 31c4739ae2908480d9dadf21f243a76d 243468 libdevel optional libdbus-1-dev_1.2.1-5+lenny1_powerpc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQEcBAEBAgAGBQJKRgxlAAoJECIIoQCMVaAczNgIAICqfraPSBLAtkqBQNJlJFTf MIz/+mxLspq7Zg8rYvRtW+0K1t9ldMHPZ0bgSoto/Zz+tmBVd41wjgL+OTNsvX2e q4HtQrIvR29Tr+4T4Wp+gLGL8WphvpDlm5pBl/htvl+MvxuSL57vS6sfNa1c8fEf GD7yQLbU7FQqOk1Eiv7tWwK19L3NoJ9OsyoUdmVf4OozRcx3Db9cMn2dvq9Lq9JF A71RgCx1hF9ssMtS+fomir2LVFuEQwd3PbercgkdfXZRy8ffIpum0j4QuJjEy7WC t5Y/T237/HiZqa3O/9ObtTIYTr+avcozOQTYHbloxf4dzUxuuE8D9sZ3Qb0Ykvc= =zXqf -----END PGP SIGNATURE-----