Opened 6 months ago

Closed 6 months ago

#23143 closed enhancement (fixed)

xdg-dbus-proxy-0.1.7

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (6)

comment:1 by Joe Locash, 6 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 6 months ago

Changes in 0.1.7
================

Released 2025-04-07

  * Drop the autotools build system
  * Unbreak the CI
  * Prevent a crash on disconnect
  * Fix building with glibc >= 2.43
  * Fix the eavesdrop filtering to prevent message interception

Fixed at 102432fbb7. Leaving open for SA.

comment:3 by Joe Locash, 6 months ago

Owner: changed from Joe Locash to Douglas R. Reno
Status: assigned → new

comment:4 by Bruce Dubbs, 6 months ago

Owner: changed from Douglas R. Reno to SecurityAdvisory

comment:5 by Douglas R. Reno, 6 months ago

Priority: normal → high

CVE-2026-34080 is rated as High and is for the eavesdropping vulnerability. It allows clients to intercept D-Bus messages that they shouldn't have access to.

comment:6 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-042 issued. I noted that the only known user in the book is WebKitGTK as well

Note: See TracTickets for help on using tickets.