# blocker for #503532 (CVE-2008-4311)
severity 510744 serious
block 503532 by 510744
user [email protected]
usertags 510744 + CVE-2008-4311
thanks

Actually, this is RC, as it blocks the fix for #503532. During normal
operation, processes in system-tools-backends call Introspect on each other,
which is no longer allowed:

Jan  4 18:37:29 replica dbus-daemon: Rejected send message, 1 matched rules; 
type="method_call", sender=":1.2" (uid=0 pid=14213 
comm="/usr/bin/system-tools-backends ") 
interface="org.freedesktop.DBus.Introspectable" member="Introspect" error 
name="(unset)" requested_reply=0 
destination="org.freedesktop.SystemToolsBackends.Platform" (uid=0 pid=14701 
comm="/usr/bin/perl /usr/share//system-tools-backends-2."))
 
I'm looking into it.

    Simon

Attachment: signature.asc
Description: Digital signature

Reply via email to