[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Possible MBF due to DBus security issue



Test results mentioned are for a laptop with a freshly installed lenny system,
the (GNOME) desktop task, the tested packages, my release candidate
version of dbus, and patched versions of hal and system-tools-backends
as seen below. Some packages haven't been tested yet - I'm not confident
that I know how they're *meant* to work, and I think the best time to
test these would be after uploading fixed dbus and hal packages to
unstable.

"Non-RC rule confusion" refers to
<http://bugs.freedesktop.org/show_bug.cgi?id=18961>.

On Sat, 03 Jan 2009 at 20:57:00 +0000, Simon McVittie wrote:
> After removing Uploaders and cross-referencing against fd.o #18980 (up to and
> including Comment #12, https://bugs.freedesktop.org/show_bug.cgi?id=18980#c12):
> 
> > Michael Biebl <biebl@debian.org>
> >    knetworkmanager
> 
> https://bugzilla.redhat.com/show_bug.cgi?id=475468

Non-RC rule confusion, works on test laptop

> >    powersave

Non-RC rule confusion, trivial tests work

> > Julien BLACHE <jblache@debian.org>
> >    pommed
> 
> Maintainer responding

RC, fixed in unstable by a new upstream release, aiming for lenny. Not
tested by Cambridge BSP, but the maintainer tested it with dbus from
experimental.

> > Debian Bluetooth Maintainers <pkg-bluetooth-maintainers@lists.alioth.debian.org>
> >    bluez-utils
> 
> http://git.kernel.org/?p=bluetooth/bluez.git;a=blob_plain;f=src/bluetooth.conf;hb=06637b08f721e1565fa05b818adfb8a0acec804e

RC, upstream patch doesn't seem to work, maintainer is investigating.

> > Debian CUPS Maintainers <pkg-cups-devel@lists.alioth.debian.org>
> >    cups

Seems non-RC

> > Debian Maemo Maintainers <pkg-maemo-maintainers@lists.alioth.debian.org>
> >    libosso

RC, totally broken security policy adds allow-by-default even if dbus-daemon
doesn't have it - maintainers pinged, RC bug filed, RM from lenny suggested

> >    osso-gwconnect

Depends on libosso and will share its fate, so I won't bother
investigating unless/until libosso is fixed

> > Debian OLPC <debian-olpc-devel@lists.alioth.debian.org>
> >    sugar
> 
> Unlikely to be on the system bus, I'll verify

Non-RC rule confusion (it is indeed on the system bus, because it contains an
equivalent of nm-applet); works on the test laptop

> > Debian VoIP Team <pkg-voip-maintainers@lists.alioth.debian.org>
> >    mumble

Looks OK, not tested

> > Debian/Ubuntu wpasupplicant Maintainers <pkg-wpa-devel@lists.alioth.debian.org>
> >    wpasupplicant

Non-RC rule confusion, works on test laptop (at least when driven by
NetworkManager)

> > Soren Hansen <soren@ubuntu.com>
> >    network-manager-openvpn

Non-RC rule confusion found, not tested but should work

> >    network-manager-vpnc

Non-RC rule confusion found, not tested but should work

> > Matthew Johnson <mjj29@debian.org>
> >    bluemon

Fixed in sid (maintainer tested with experimental dbus), migration requested

> > Simon Kelley <simon@thekelleys.org.uk>
> >    dnsmasq

Non-RC rule confusion found, trivially tested on my laptop, seems to work

> > Anand Kumria <wildfire@progsoc.org>
> >    yum

Non-RC rule confusion found, not tested but should work

> > Jonny Lamb <jonnylamb@jonnylamb.com>
> >    odccm

Non-RC rule confusion found, not tested but should work

> > Patrick Patterson <ppatters@debian.org>
> >    pathfinder

Non-RC rule confusion found, not tested but should work

> > Otavio Salvador <otavio@debian.org>
> >    system-config-printer

Non-RC rule confusion found, works on test laptop

> > Riccardo Setti <giskard@debian.org>
> >    galago-daemon
> 
> Unlikely to be on the system bus, I'll verify

Isn't actually on the system bus, so its config should be a no-op

> > Jose Carlos Garcia Sogo <jsogo@debian.org>
> >    system-tools-backends

RC bug with suggested patch

> > Brian Sutherland <jinty@web.de>
> >    smart-notifier

Non-RC rule confusion found, not tested

> > Enrico Tassi <gareuselesinge@debian.org>
> >    network-manager-pptp

Non-RC rule confusion found, not tested

> > Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
> >    avahi

Non-RC rule confusion found, seems to work, might have minor privilege
escalation (ability to SetHostName without being in netdev)

> >    consolekit
> 
> http://bugs.freedesktop.org/show_bug.cgi?id=19020

RC (introspection disallowed), rules are subtle enough that it
needs to be tested by someone who understands it fully

> >    dhcdbd

Non-RC rule confusion, works on test laptop at least when invoked by
NetworkManager

> >    hal
> 
> https://bugs.freedesktop.org/show_bug.cgi?id=18985

Some functionality no longer works; I've proposed a patch which
worked on my test laptop for powersaved, NetworkManager and
gnome-power-manager didn't complain

> >    network-manager

Non-RC rule confusion, works on test laptop

> >    network-manager-applet

Non-RC rule confusion, works on test laptop

> >    policykit
> 
> https://bugs.freedesktop.org/show_bug.cgi?id=18948

RC bug filed, trivial patch accepted upstream, maintainer aware

> > Matthew Wilcox <willy@debian.org>
> >    kerneloops

Looks OK, not tested

> > Neil Williams <codehelp@debian.org>
> >    gpe-bluetooth
> 
> Maintainer will investigate

Looks OK, tested by maintainer with experimental dbus

Attachment: signature.asc
Description: Digital signature


Reply to: