Your message dated Wed, 07 Jan 2009 17:17:04 +0000
with message-id <e1lkc1g-0001xf...@ries.debian.org>
and subject line Bug#510645: fixed in consolekit 0.2.10-4
has caused the Debian Bug report #510645,
regarding consolekit: /etc/dbus-1/system.d file needs alterations for fd.o 
#18961
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
510645: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=510645
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: consolekit
Version: 0.2.10-3
Severity: normal
User: pkg-utopia-maintain...@lists.alioth.debian.org
Usertags: fdo-18961

consolekit's D-Bus system.d config should be updated to fix
non-deterministic allow/deny for messages with no interface; the D-Bus
upstream recommendation seems to be that every allow or deny rule with
send_interface="..." should have a suitable send_destination attribute too.

http://bugs.freedesktop.org/show_bug.cgi?id=18961 is the D-Bus bug tracking
this; there have also been discussions on the D-Bus mailing list.

Please test the resulting package against the dbus package from
http://people.debian.org/~smcv/dbus-cve-2008-4311/ (you might be better
off waiting until hal's current RC bug has been fixed before you
upgrade). ConsoleKit.conf is subtle enough that I don't feel confident
that I can suggest a correct configuration...

Regards from the Cambridge BSP,
    Simon

Attachment: signature.asc
Description: Digital signature


--- End Message ---
--- Begin Message ---
Source: consolekit
Source-Version: 0.2.10-4

We believe that the bug you reported is fixed in the latest version of
consolekit, which is due to be installed in the Debian FTP archive:

consolekit_0.2.10-4.diff.gz
  to pool/main/c/consolekit/consolekit_0.2.10-4.diff.gz
consolekit_0.2.10-4.dsc
  to pool/main/c/consolekit/consolekit_0.2.10-4.dsc
consolekit_0.2.10-4_i386.deb
  to pool/main/c/consolekit/consolekit_0.2.10-4_i386.deb
libck-connector-dev_0.2.10-4_i386.deb
  to pool/main/c/consolekit/libck-connector-dev_0.2.10-4_i386.deb
libck-connector0_0.2.10-4_i386.deb
  to pool/main/c/consolekit/libck-connector0_0.2.10-4_i386.deb
libpam-ck-connector_0.2.10-4_i386.deb
  to pool/main/c/consolekit/libpam-ck-connector_0.2.10-4_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 510...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Biebl <bi...@debian.org> (supplier of updated consolekit package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Wed, 07 Jan 2009 17:58:29 +0100
Source: consolekit
Binary: consolekit libck-connector0 libck-connector-dev libpam-ck-connector
Architecture: source i386
Version: 0.2.10-4
Distribution: unstable
Urgency: high
Maintainer: Utopia Maintenance Team 
<pkg-utopia-maintain...@lists.alioth.debian.org>
Changed-By: Michael Biebl <bi...@debian.org>
Description: 
 consolekit - framework for defining and tracking users, sessions and seats
 libck-connector-dev - ConsoleKit development files
 libck-connector0 - ConsoleKit libraries
 libpam-ck-connector - ConsoleKit PAM module
Closes: 510645
Changes: 
 consolekit (0.2.10-4) unstable; urgency=high
 .
   [ Michael Biebl ]
   * debian/watch
     - Check for both .gz and .bz2 tarballs.
   * debian/control
     - Add ${misc:Depends} to libck-connector-dev.
 .
   [ Simon McVittie ]
   * debian/patches/05-dbus_policy.patch: patch from
     Colin Walters so ConsoleKit introspection and SetIdleHint still work
     after CVE-2008-4311 is fixed in dbus-daemon. (Closes: #510645)
   * Urgency high for bugfix that blocks CVE-2008-4311 upload.
Checksums-Sha1: 
 4aa3a2dbe9aad0a44ccdefd96a95267a0b84f268 1484 consolekit_0.2.10-4.dsc
 7c13eac72dd8ef77040b3ed89eeff1a693cd777e 8289 consolekit_0.2.10-4.diff.gz
 5690439056920269ac00b41385d3904f8a60a525 125918 consolekit_0.2.10-4_i386.deb
 eb516e12e8bd27277987c40627f4cab7b41627fb 41316 
libck-connector0_0.2.10-4_i386.deb
 f064152dacf266fbccfe43019ec7e296cd175208 48806 
libck-connector-dev_0.2.10-4_i386.deb
 c29c94ad7935aefc03d6ab78360945a7841ce2c0 41548 
libpam-ck-connector_0.2.10-4_i386.deb
Checksums-Sha256: 
 73e85ff04035a1903abfa9dba63fc5766be80c5efca336d255b78eb9f87cf2f3 1484 
consolekit_0.2.10-4.dsc
 b8ca2684bd9492db13cf9529341e5a902e843ccb0dc40d1084d44934cc395d91 8289 
consolekit_0.2.10-4.diff.gz
 44a60907af4d42395c2d84a6cb6c19030c2f297d931a68445236d37997831aca 125918 
consolekit_0.2.10-4_i386.deb
 cd9589457fb3a94c4d0b0e67ea17cfb5eeaaeb8dde0dbb1955a4a4372d8233d4 41316 
libck-connector0_0.2.10-4_i386.deb
 ae40a859d874970824284a014c45e3977a5b30ca5b8486b247eef659447c667d 48806 
libck-connector-dev_0.2.10-4_i386.deb
 66211e750da1f39b995976d9e1862b5bea0083e7fb3ed2bb1873eab95fa7a074 41548 
libpam-ck-connector_0.2.10-4_i386.deb
Files: 
 2c707cd7fa62665d89ff380bccbe73b1 1484 admin optional consolekit_0.2.10-4.dsc
 c4e6f80c35b541f035440290b5285da2 8289 admin optional 
consolekit_0.2.10-4.diff.gz
 2089768bd86726359222952142c924a8 125918 admin optional 
consolekit_0.2.10-4_i386.deb
 2c08386d0244d9f9343b1b50de094756 41316 libs optional 
libck-connector0_0.2.10-4_i386.deb
 f6d977d10e9dd909a6e52d4fefcd8ded 48806 libdevel optional 
libck-connector-dev_0.2.10-4_i386.deb
 b81505b7a924d63cc19c0f13135ba6ae 41548 admin optional 
libpam-ck-connector_0.2.10-4_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAklk39kACgkQh7PER70FhVTMlQCgi2tThL0HFn/VP5FV7CPxANFp
jXIAoIC+yo96jQbzod3pJtQH9NppfUCp
=kpSF
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to