Package: wpasupplicant Version: 0.6.4-3 Severity: normal User: pkg-utopia-maintain...@lists.alioth.debian.org Usertags: fdo-18961
wpasupplicant's D-Bus system.d config should be updated to fix non-deterministic allow/deny for messages with no interface (related to CVE-2008-4311). http://bugs.freedesktop.org/show_bug.cgi?id=18961 is the D-Bus bug tracking this. It appears from the dnsmasq patch there that removing the lines <allow send_interface="..."/> and <deny send_interface="..."/> is recommended (the fact that send_destination is allowed should be sufficient). Regards from the Cambridge BSP, Simon
signature.asc
Description: Digital signature