On Sunday 04 January 2009 12:10:03 Simon McVittie wrote: > Package: wpasupplicant > Version: 0.6.4-3 > Severity: normal > User: pkg-utopia-maintain...@lists.alioth.debian.org > Usertags: fdo-18961 > > wpasupplicant's D-Bus system.d config should be updated to fix > non-deterministic allow/deny for messages with no interface (related to > CVE-2008-4311). > > http://bugs.freedesktop.org/show_bug.cgi?id=18961 is the D-Bus bug tracking > this. It appears from the dnsmasq patch there that removing the lines > <allow send_interface="..."/> and <deny send_interface="..."/> is recommended > (the fact that send_destination is allowed should be sufficient).
Is this likely to be needed in wpasupplicant package for Lenny release? Thanks, Kel. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org