Sun Jul 6 14:54:32 2014 UTC ()
Update to 1.8.6:

D-Bus 1.8.6 (2014-06-02)
==

Security fixes:

• On Linux ≥ 2.6.37-rc4, if sendmsg() fails with ETOOMANYREFS, silently drop
  the message. This prevents an attack in which a malicious client can
  make dbus-daemon disconnect a system service, which is a local
  denial of service.
  (fd.o #80163, CVE-2014-3532; Alban Crequy)

• Track remaining Unix file descriptors correctly when more than one
  message in quick succession contains fds. This prevents another attack
  in which a malicious client can make dbus-daemon disconnect a system
  service.
  (fd.o #79694, fd.o #80469, CVE-2014-3533; Alejandro Martínez Suárez,
  Simon McVittie, Alban Crequy)

Other fixes:

• When dbus-launch --exit-with-session starts a dbus-daemon but then cannot
  attach to a session, kill the dbus-daemon as intended
  (fd.o #74698, Роман Донченко)


(wiz)
diff -r1.71 -r1.72 pkgsrc/sysutils/dbus/Makefile
diff -r1.56 -r1.57 pkgsrc/sysutils/dbus/distinfo

cvs diff -r1.71 -r1.72 pkgsrc/sysutils/dbus/Makefile (expand / switch to unified diff)

--- pkgsrc/sysutils/dbus/Makefile 2014/06/14 21:59:20 1.71
+++ pkgsrc/sysutils/dbus/Makefile 2014/07/06 14:54:32 1.72
@@ -1,17 +1,16 @@ @@ -1,17 +1,16 @@
1# $NetBSD: Makefile,v 1.71 2014/06/14 21:59:20 wiz Exp $ 1# $NetBSD: Makefile,v 1.72 2014/07/06 14:54:32 wiz Exp $
2 2
3DISTNAME= dbus-1.8.4 3DISTNAME= dbus-1.8.6
4PKGREVISION= 1 
5CATEGORIES= sysutils 4CATEGORIES= sysutils
6MASTER_SITES= http://dbus.freedesktop.org/releases/dbus/ 5MASTER_SITES= http://dbus.freedesktop.org/releases/dbus/
7 6
8MAINTAINER= pkgsrc-users@NetBSD.org 7MAINTAINER= pkgsrc-users@NetBSD.org
9HOMEPAGE= http://www.freedesktop.org/Software/dbus 8HOMEPAGE= http://www.freedesktop.org/Software/dbus
10COMMENT= Message bus system 9COMMENT= Message bus system
11LICENSE= gnu-gpl-v2 10LICENSE= gnu-gpl-v2
12 11
13CONFLICTS+= dbus-glib<0.71 12CONFLICTS+= dbus-glib<0.71
14CONFLICTS+= py26-dbus<0.71 13CONFLICTS+= py26-dbus<0.71
15CONFLICTS+= py27-dbus<0.71 14CONFLICTS+= py27-dbus<0.71
16 15
17GNU_CONFIGURE= YES 16GNU_CONFIGURE= YES

cvs diff -r1.56 -r1.57 pkgsrc/sysutils/dbus/distinfo (expand / switch to unified diff)

--- pkgsrc/sysutils/dbus/distinfo 2014/06/14 21:57:34 1.56
+++ pkgsrc/sysutils/dbus/distinfo 2014/07/06 14:54:32 1.57
@@ -1,13 +1,13 @@ @@ -1,13 +1,13 @@
1$NetBSD: distinfo,v 1.56 2014/06/14 21:57:34 wiz Exp $ 1$NetBSD: distinfo,v 1.57 2014/07/06 14:54:32 wiz Exp $
2 2
3SHA1 (dbus-1.8.4.tar.gz) = 316f1196312a88cc858ba810d4e5d16f70ab9d58 3SHA1 (dbus-1.8.6.tar.gz) = ad7cb87cdce66533479a9d7c1c956bdb0243ad87
4RMD160 (dbus-1.8.4.tar.gz) = 929ec1d4ff1a1087fc4ca920f49ee6f89d55b3b7 4RMD160 (dbus-1.8.6.tar.gz) = 78dcfa48f4d780b27a8c144e481bc285fcf5fd62
5Size (dbus-1.8.4.tar.gz) = 1860286 bytes 5Size (dbus-1.8.6.tar.gz) = 1861784 bytes
6SHA1 (patch-aa) = 0c3d145979e3b2358261c9f7f34701d02eb6ecd4 6SHA1 (patch-aa) = 0c3d145979e3b2358261c9f7f34701d02eb6ecd4
7SHA1 (patch-ak) = 6d05ebde29acb3f6cb6f577dd2f2b734f590e8dd 7SHA1 (patch-ak) = 6d05ebde29acb3f6cb6f577dd2f2b734f590e8dd
8SHA1 (patch-al) = 57d08196e9daf49eb6bda2b30f019ce2cad77c6f 8SHA1 (patch-al) = 57d08196e9daf49eb6bda2b30f019ce2cad77c6f
9SHA1 (patch-am) = 8c794ff8b0981e90243ee20c26ae1ecc72e68de8 9SHA1 (patch-am) = 8c794ff8b0981e90243ee20c26ae1ecc72e68de8
10SHA1 (patch-ba) = f9126faf18cd19e897865748ebea1011fe516225 10SHA1 (patch-ba) = f9126faf18cd19e897865748ebea1011fe516225
11SHA1 (patch-bus_dir-watch-kqueue.c) = 86a1f0f78b4d16d8ab29d351057885d8001dd39c 11SHA1 (patch-bus_dir-watch-kqueue.c) = 86a1f0f78b4d16d8ab29d351057885d8001dd39c
12SHA1 (patch-configure) = 08fb6cc6e9bc9f23825a6a0f2b8b241169d1cda7 12SHA1 (patch-configure) = 08fb6cc6e9bc9f23825a6a0f2b8b241169d1cda7
13SHA1 (patch-dbus_dbus-sysdeps-unix.c) = 043e7bf03686f51faf763f87f43e00308b29571e 13SHA1 (patch-dbus_dbus-sysdeps-unix.c) = 043e7bf03686f51faf763f87f43e00308b29571e