From a0926ef86f413f18202ffa19cb1433b6ba00ac36 Mon Sep 17 00:00:00 2001 From: Simon McVittie Date: Tue, 2 Jun 2020 12:18:39 +0100 Subject: Prepare 1.12.18 Signed-off-by: Simon McVittie --- NEWS | 17 +++++++++++++++-- configure.ac | 4 ++-- 2 files changed, 17 insertions(+), 4 deletions(-) diff --git a/NEWS b/NEWS index 0ddddfd3..a38c5992 100644 --- a/NEWS +++ b/NEWS @@ -1,7 +1,20 @@ -dbus 1.12.18 (UNRELEASED) +dbus 1.12.18 (2020-06-02) ========================= -Fixes: +The “telepathic vines” release. + +Denial of service fixes: + +• CVE-2020-12049: If a message contains more file descriptors than can + be sent, close those that did get through before reporting error. + Previously, a local attacker could cause the system dbus-daemon (or + another system service with its own DBusServer) to run out of file + descriptors, by repeatedly connecting to the server and sending fds that + would get leaked. + Thanks to Kevin Backhouse of GitHub Security Lab. + (dbus#294, GHSL-2020-057; Simon McVittie) + +Other fixes: • Fix a crash when the dbus-daemon is terminated while one or more monitors are active (dbus#291, dbus!140; Simon McVittie) diff --git a/configure.ac b/configure.ac index a1ba877a..0601c421 100644 --- a/configure.ac +++ b/configure.ac @@ -3,7 +3,7 @@ AC_PREREQ([2.63]) m4_define([dbus_major_version], [1]) m4_define([dbus_minor_version], [12]) -m4_define([dbus_micro_version], [17]) +m4_define([dbus_micro_version], [18]) m4_define([dbus_version], [dbus_major_version.dbus_minor_version.dbus_micro_version]) AC_INIT([dbus],[dbus_version],[https://bugs.freedesktop.org/enter_bug.cgi?product=dbus],[dbus]) @@ -42,7 +42,7 @@ LT_CURRENT=22 ## increment any time the source changes; set to ## 0 if you increment CURRENT -LT_REVISION=11 +LT_REVISION=12 ## increment if any interfaces have been added; set to 0 ## if any interfaces have been changed or removed. removal has -- cgit v1.2.1