Package: wpasupplicant
Version: 0.6.4-3
Severity: normal
User: pkg-utopia-maintain...@lists.alioth.debian.org
Usertags: fdo-18961

wpasupplicant's D-Bus system.d config should be updated to fix
non-deterministic allow/deny for messages with no interface (related to
CVE-2008-4311).

http://bugs.freedesktop.org/show_bug.cgi?id=18961 is the D-Bus bug tracking
this. It appears from the dnsmasq patch there that removing the lines
<allow send_interface="..."/> and <deny send_interface="..."/> is recommended
(the fact that send_destination is allowed should be sufficient).

Regards from the Cambridge BSP,
    Simon

Attachment: signature.asc
Description: Digital signature

Reply via email to