From: John (J5) Palmieri Date: Tue, 26 Feb 2008 19:32:57 +0000 (-0500) Subject: Released 1.0.3 X-Git-Tag: DBUS_1_0_3^0 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=3252e713c52f80831080c4e0bb25543f3746e3de;p=thirdparty%2Fdbus.git Released 1.0.3 --- diff --git a/ChangeLog b/ChangeLog index 4f6ee7c60..416c1a86f 100644 --- a/ChangeLog +++ b/ChangeLog @@ -1,3 +1,7 @@ +2008-02-26 John (J5) Palmieri + + * Released 1.0.3 + 2008-02-26 John (J5) Palmieri * CVE-2008-0595 - security policy of the type work as an implicit allow for + messages sent without an interface bypassing the default deny rules and + potentially allowing restricted methods exported on the bus to be executed + by unauthorized users. +- correctly unref connections without guids during shutdown +- don't mess with message from message cache outside of the cache lock +- avoid trying to protect individual bits in a word with different locks +- fix to allow a server to use port=0 or omit port so the port can be + auto-selected by the OS +- add session.d for the session bus, so security policy can be extended +- capture the dbus-launch stderr output and add it to the DBusError message we + return. +- add option --close-stderr to close stderr before starting dbus-daemon +- session bus now has higher limits by default + D-Bus 1.0.2 (12 December 2006) == - Fix security bug CVE-2006-6107 match rules can be removed by apps that did