Comment 17 for bug 230877

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package dbus - 1.2.4-0ubuntu1

---------------
dbus (1.2.4-0ubuntu1) intrepid; urgency=low

  * New upstream bug fix release: (LP: #279425)
    - Fix crash on dbus_signature_validate("a{(ii)i}", NULL), which would
      unexpectedly abort the calling program. [CVE-2008-3834]
    - Close file descriptors before exec()ing helpers, to avoid locking
      hardware like video cards by eternally open file fds. (LP: #230877)
    - A small number of compilation and portability fixes.

 -- Martin Pitt <email address hidden> Tue, 07 Oct 2008 15:26:32 +0200