A call to dbus_signature_validate() can crash dbus. Patch: http://gitweb.freedesktop.org/?p=dbus/dbus.git;a=commit;h=7b10b46c5c8658449783ce45f1273dd35c353bce
Arches, please test and mark stable: =sys-apps/dbus-1.2.3-r1 Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"
ppc64 stable
amd64/x86 stable
Stable for HPPA.
sparc stable
alpha/ia64 stable
CVE-2008-3834 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3834): The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.
ppc stable
Ready for vote, I vote YES.
Ok, YES then.
arm/s390/sh stable
GLSA 200901-04