-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Sat, 15 Jan 2011 14:54:45 +0000 Source: dbus Binary: dbus dbus-x11 libdbus-1-3 dbus-1-doc libdbus-1-dev Architecture: i386 Version: 1.2.1-5+lenny2 Distribution: stable-security Urgency: high Maintainer: i386 Build Daemon (murphy) Changed-By: Nico Golde Description: dbus - simple interprocess messaging system dbus-1-doc - simple interprocess messaging system (documentation) dbus-x11 - simple interprocess messaging system (X11 deps) libdbus-1-3 - simple interprocess messaging system libdbus-1-dev - simple interprocess messaging system (development headers) Changes: dbus (1.2.1-5+lenny2) stable-security; urgency=high . * Non-maintainer upload by the Security Team. * Backport upstream patch to fix a possible call stack overflow and thus denial of service, when processing messages with excessive nested variants. This fix restricts the nesting level to 64 (52-CVE-2010-4352.patch). Checksums-Sha1: ed3d63c1cfd8ae807d4a59a580ec430bf121fa6e 229914 dbus_1.2.1-5+lenny2_i386.deb 0ef36dee589d7f8e078792cbd7ed45d2f8881fd4 64384 dbus-x11_1.2.1-5+lenny2_i386.deb 84ca44fda04ac87d937037f5a647228521e90d7d 148480 libdbus-1-3_1.2.1-5+lenny2_i386.deb 6c43901e839afa386e593288f2bfd0708689afb3 235002 libdbus-1-dev_1.2.1-5+lenny2_i386.deb Checksums-Sha256: cb4ae484d58decd64342a6f9a309064b26c6ef1281725111cf6ac9bdf6a4b440 229914 dbus_1.2.1-5+lenny2_i386.deb 705d8f445c6e81f21981d0ad335b65c1bff2b62e22336dea40d3f0a6148daba9 64384 dbus-x11_1.2.1-5+lenny2_i386.deb bf1a195ce29d3a44f1b1489109e25aee932230c4da7b2055aa5e9968f0c84995 148480 libdbus-1-3_1.2.1-5+lenny2_i386.deb 4c2aaef8df7dc34fad7dc7f19d20138562799c5c7ead926eeabe2e0ec07c566d 235002 libdbus-1-dev_1.2.1-5+lenny2_i386.deb Files: f46bc4c5ec7a5b9c7ade59182826a8c8 229914 devel optional dbus_1.2.1-5+lenny2_i386.deb 32f91804645c65c031e4bc7764047379 64384 x11 optional dbus-x11_1.2.1-5+lenny2_i386.deb 1a6385c87880fdb61fd4ce1add4bde54 148480 libs optional libdbus-1-3_1.2.1-5+lenny2_i386.deb f486b9a905f1b89f9b027e04b54b992d 235002 libdevel optional libdbus-1-dev_1.2.1-5+lenny2_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk00QPYACgkQHYflSXNkfP8n/gCgjxsUkEmVoXkoWYVaDNrrzslh yBMAnA1R/GPaU9oOaofyBMn3u8gw0tb8 =o1f3 -----END PGP SIGNATURE-----