Home | Docs | Forums | Lists | Bugs | Planet | Store | GMN | Get Gentoo!
Not eligible to see or edit group visibility for this bug.
View Bug Activity | Format For Printing | XML | Clone This Bug
A call to dbus_signature_validate() can crash dbus. Patch: http://gitweb.freedesktop.org/?p=dbus/dbus.git;a=commit;h=7b10b46c5c8658449783ce45f1273dd35c353bce
Arches, please test and mark stable: =sys-apps/dbus-1.2.3-r1 Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"
ppc64 stable
amd64/x86 stable
Stable for HPPA.
sparc stable
alpha/ia64 stable
CVE-2008-3834 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3834): The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.
ppc stable
Ready for vote, I vote YES.
Ok, YES then.
arm/s390/sh stable
GLSA 200901-04