summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorSimon McVittie <smcv@collabora.com>2020-06-02 12:18:39 +0100
committerSimon McVittie <smcv@collabora.com>2020-06-02 12:18:39 +0100
commita0926ef86f413f18202ffa19cb1433b6ba00ac36 (patch)
tree05b22dcb75e158074e36fe7f882480fe38864ad4
parent8bc1381819e5a845331650bfa28dacf6d2ac1748 (diff)
Prepare 1.12.18dbus-1.12.18
Signed-off-by: Simon McVittie <smcv@collabora.com>
-rw-r--r--NEWS17
-rw-r--r--configure.ac4
2 files changed, 17 insertions, 4 deletions
diff --git a/NEWS b/NEWS
index 0ddddfd3..a38c5992 100644
--- a/NEWS
+++ b/NEWS
@@ -1,7 +1,20 @@
-dbus 1.12.18 (UNRELEASED)
+dbus 1.12.18 (2020-06-02)
=========================
-Fixes:
+The “telepathic vines” release.
+
+Denial of service fixes:
+
+• CVE-2020-12049: If a message contains more file descriptors than can
+ be sent, close those that did get through before reporting error.
+ Previously, a local attacker could cause the system dbus-daemon (or
+ another system service with its own DBusServer) to run out of file
+ descriptors, by repeatedly connecting to the server and sending fds that
+ would get leaked.
+ Thanks to Kevin Backhouse of GitHub Security Lab.
+ (dbus#294, GHSL-2020-057; Simon McVittie)
+
+Other fixes:
• Fix a crash when the dbus-daemon is terminated while one or more
monitors are active (dbus#291, dbus!140; Simon McVittie)
diff --git a/configure.ac b/configure.ac
index a1ba877a..0601c421 100644
--- a/configure.ac
+++ b/configure.ac
@@ -3,7 +3,7 @@ AC_PREREQ([2.63])
m4_define([dbus_major_version], [1])
m4_define([dbus_minor_version], [12])
-m4_define([dbus_micro_version], [17])
+m4_define([dbus_micro_version], [18])
m4_define([dbus_version],
[dbus_major_version.dbus_minor_version.dbus_micro_version])
AC_INIT([dbus],[dbus_version],[https://bugs.freedesktop.org/enter_bug.cgi?product=dbus],[dbus])
@@ -42,7 +42,7 @@ LT_CURRENT=22
## increment any time the source changes; set to
## 0 if you increment CURRENT
-LT_REVISION=11
+LT_REVISION=12
## increment if any interfaces have been added; set to 0
## if any interfaces have been changed or removed. removal has