]> git.ipfire.org Git - thirdparty/dbus.git/commitdiff
NEWS: Add #421
authorSimon McVittie <smcv@collabora.com>
Wed, 8 Feb 2023 10:47:08 +0000 (10:47 +0000)
committerSimon McVittie <smcv@collabora.com>
Wed, 8 Feb 2023 12:03:30 +0000 (12:03 +0000)
Signed-off-by: Simon McVittie <smcv@collabora.com>
NEWS

diff --git a/NEWS b/NEWS
index b144a8186eb781a5cbea2ee3411a3ecd381dc836..31da9e3481aa16f78dbadcd8408606aa0aa3ddf3 100644 (file)
--- a/NEWS
+++ b/NEWS
@@ -38,6 +38,15 @@ New features:
   strongly recommended. See test/use-as-subproject for sample code.
   (dbus!368, dbus!388; Daniel Wagner)
 
+Denial of service fixes:
+
+• Fix an incorrect assertion that could be used to crash dbus-daemon or
+  other users of DBusServer prior to authentication, if libdbus was compiled
+  with assertions enabled.
+  We recommend that production builds of dbus, for example in OS distributions,
+  should be compiled with checks but without assertions.
+  (dbus#421, Ralf Habacker; thanks to Evgeny Vereshchagin)
+
 Fixes:
 
 • When connected to a dbus-broker, stop dbus-monitor from incorrectly