From: Simon McVittie Date: Fri, 11 Nov 2016 19:47:40 +0000 (+0000) Subject: Update NEWS X-Git-Tag: dbus-1.11.8~18 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=2ebcebf2e52266e99baee4c4d9d9a54ff6c12feb;p=thirdparty%2Fdbus.git Update NEWS --- diff --git a/NEWS b/NEWS index adcfef471..f2f347c91 100644 --- a/NEWS +++ b/NEWS @@ -17,7 +17,20 @@ Enhancements: • Fix and enable a lot of compiler warnings to improve future code quality. This might incidentally also fix some environment variable accesses on OS X. - (fd.o #97357, fd.o #98192, fd.o #98195; Thomas Zimmermann, Simon McVittie) + (fd.o #97357, fd.o #98192, fd.o #98195, fd.o #98658; + Thomas Zimmermann, Simon McVittie) + +Fixes: + +• Work around an undesired effect of the fix for CVE-2014-3637 + (fd.o #80559), in which processes that frequently send fds, such as + logind during a flood of new PAM sessions, can get disconnected for + continuously having at least one fd "in flight" for too long; + dbus-daemon interprets that as a potential denial of service attack. + The workaround is to disable that check for uid 0 process such as + logind, with a message in the system log. The bug remains open while + we look for a more general solution. + (fd.o #95263, LP#1591411; Simon McVittie) D-Bus 1.11.6 (2016-10-10) ==