Bug#930375: CVE-2019-12749: DBusServer DBUS_COOKIE_SHA1 authentication bypass

2019-06-11 Thread Simon McVittie
Package: libdbus-1-3 Version: 1.0.0-1 Severity: grave Tags: security fixed-upstream patch Forwarded: https://gitlab.freedesktop.org/dbus/dbus/issues/269 Joe Vennix of Apple Information Security discovered an implementation flaw in the DBUS_COOKIE_SHA1 authentication mechanism. A malicious client w

Bug#930376: gvfsd GetConnection() missing authorization check

2019-06-11 Thread Simon McVittie
Package: gvfs-daemons Version: 1.14.1-1 Severity: grave Tags: security fixed-upstream patch Forwarded: https://gitlab.gnome.org/GNOME/gvfs/commit/70dbfc68a79faac49bd3423e079cb6902522082a While looking for services that might be vulnerable to CVE-2019-12749 or a similar vulnerability, I noticed th