Bug#510636: libosso: Has a dbus config file which circumvents all security messages on the system bus

Matthew Johnson mjj29 at debian.org
Sat Jan 3 22:53:08 UTC 2009


Package: libosso
Version: 2.15.debian.1-1
Severity: grave
Tags: security

libosso1 ships /etc/dbus-1/system.d/libosso.conf which turns off all the
security checks on the system bus by allowing all messages from everyone
to everyone else. This is bad mkay?

-- System Information:
Debian Release: lenny/sid
  APT prefers testing
  APT policy: (500, 'testing'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.18-4-686 (SMP w/2 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash





More information about the pkg-maemo-maintainers mailing list