nixpkgs/pkgs/development/libraries/dbus
Will Dietz 6d7cdd7f8b dbus: 1.12.14 -> 1.12.16
https://gitlab.freedesktop.org/dbus/dbus/blob/dbus-1.12.16/NEWS

It's short and explains the CVE a bit, including below:

> CVE-2019-12749: Do not attempt to carry out DBUS_COOKIE_SHA1
> authentication for identities that differ from the user running the
> DBusServer. Previously, a local attacker could manipulate symbolic
> links in their own home directory to bypass authentication and connect
> to a DBusServer with elevated privileges. The standard system and
> session dbus-daemons in their default configuration were immune to this
> attack because they did not allow DBUS_COOKIE_SHA1, but third-party
> users of DBusServer such as Upstart could be vulnerable.   Thanks to Joe
> Vennix of Apple Information Security.   (dbus#269, Simon McVittie)
2019-06-15 18:16:58 +02:00
..
default.nix dbus: 1.12.14 -> 1.12.16 2019-06-15 18:16:58 +02:00
implement-getgrouplist.patch
make-dbus-conf.nix makeDBusConfig: don't allow substitutions 2019-03-17 16:04:08 +00:00
make-session-conf.xsl
make-system-conf.xsl
systemd.patch dbus: modularize into libs, daemon, tools, tests and docs 2013-04-04 22:00:46 +02:00