Report forwarded
to debian-bugs-dist@lists.debian.org, Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>: Bug#502408; Package dbus.
(Thu, 16 Oct 2008 10:18:07 GMT) (full text, mbox, link).
Acknowledgement sent
to Michael Cree <mcree@orcon.net.nz>:
New Bug report received and forwarded. Copy sent to Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>.
(Thu, 16 Oct 2008 10:18:07 GMT) (full text, mbox, link).
Package: dbus
Version: 1.2.1-3
Severity: normal
Tags: patch
dbus and libdbus-1 generate unaligned traps on the Alpha architecture.
The traps are due to misaligned accesses. On Alpha they generate a
kernel trap and the kernel simulates the memory access with an
"unaligned trap" entry in the kernel log. This is not a show-stopper on
Alpha but the frequency of the reports in the system log is quite
annoying. As the misaligned memory access is also in libdbus-1 it
pollutes other programs that use libdbus-1 (see bug #368863 for the hal
package where the unaligned trap is, in fact, due to libdbus-1).
The offending line of code is line 518 of dbus_marshal_basic.c and I
attach a patch (assuming this reportbug thingy works as I expect) recently
posted by Jay Estabrook of HP to the debian-alpha mail list. I have
been running dbus 1.2.1-3 with the patch applied for the last few days
with no unaligned traps and no problems.
-- System Information:
Debian Release: lenny/sid
APT prefers testing
APT policy: (500, 'testing')
Architecture: alpha
Kernel: Linux 2.6.26.2-dp264
Locale: LANG=en_NZ, LC_CTYPE=en_NZ (charmap=ISO-8859-1)
Shell: /bin/sh linked to /bin/bash
Versions of packages dbus depends on:
ii adduser 3.110 add and remove users and groups
ii debianutils 2.30 Miscellaneous utilities specific t
ii libc6.1 2.7-13 GNU C Library: Shared libraries
ii libdbus-1-3 1.2.1-3 simple interprocess messaging syst
ii libexpat1 2.0.1-4 XML parsing C library - runtime li
ii libselinux1 2.0.65-5 SELinux shared libraries
ii lsb-base 3.2-20 Linux Standard Base 3.2 init scrip
Versions of packages dbus recommends:
ii dbus-x11 1.2.1-3 simple interprocess messaging syst
dbus suggests no packages.
-- no debconf information
Source: dbus
Source-Version: 1.2.1-4
We believe that the bug you reported is fixed in the latest version of
dbus, which is due to be installed in the Debian FTP archive:
dbus-1-doc_1.2.1-4_all.deb
to pool/main/d/dbus/dbus-1-doc_1.2.1-4_all.deb
dbus-x11_1.2.1-4_i386.deb
to pool/main/d/dbus/dbus-x11_1.2.1-4_i386.deb
dbus_1.2.1-4.diff.gz
to pool/main/d/dbus/dbus_1.2.1-4.diff.gz
dbus_1.2.1-4.dsc
to pool/main/d/dbus/dbus_1.2.1-4.dsc
dbus_1.2.1-4_i386.deb
to pool/main/d/dbus/dbus_1.2.1-4_i386.deb
libdbus-1-3_1.2.1-4_i386.deb
to pool/main/d/dbus/libdbus-1-3_1.2.1-4_i386.deb
libdbus-1-dev_1.2.1-4_i386.deb
to pool/main/d/dbus/libdbus-1-dev_1.2.1-4_i386.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 502408@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Michael Biebl <biebl@debian.org> (supplier of updated dbus package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Sat, 25 Oct 2008 15:28:05 +0200
Source: dbus
Binary: dbus dbus-x11 libdbus-1-3 dbus-1-doc libdbus-1-dev
Architecture: source all i386
Version: 1.2.1-4
Distribution: unstable
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Michael Biebl <biebl@debian.org>
Description:
dbus - simple interprocess messaging system
dbus-1-doc - simple interprocess messaging system (documentation)
dbus-x11 - simple interprocess messaging system (X11 deps)
libdbus-1-3 - simple interprocess messaging system
libdbus-1-dev - simple interprocess messaging system (development headers)
Closes: 470121501443502408
Changes:
dbus (1.2.1-4) unstable; urgency=high
.
* debian/patches/CVE-2008-3834.patch
- The dbus_signature_validate function in the D-bus library allows
attackers to cause a denial of service (application abort) via a message
containing a malformed signature, which triggers a failed assertion
error. (Closes: #501443)
Fixes: CVE-2008-3834
- Urgency high for the security fix.
* debian/patches/20-dbus-alpha-unaligned.patch
- Fix misaligned memory access which causes "unaligned traps" on Alpha.
(Closes: #502408)
* debian/dbus.init
- Add "status" action to init script. (Closes: #470121)
* debian/control
- Bump Depends on lsb-base to >= 3.2-14, which provides status_of_proc().
Checksums-Sha1:
8d180027e8b2f892130d557176b70451b21dec9d 1536 dbus_1.2.1-4.dsc
57f92495c731bf1ad921ca3a96753b5d0b3a74c9 27997 dbus_1.2.1-4.diff.gz
5b7878ed83757e73c3b1ff780535e4a1f24b7698 1819304 dbus-1-doc_1.2.1-4_all.deb
3c5cd42441fcbeb7b18de4b81f03eaea497810f1 226896 dbus_1.2.1-4_i386.deb
b40aab7ef9fb9d39094e9945ababb634c1e6b164 63376 dbus-x11_1.2.1-4_i386.deb
44f354577f02dd3d1bdea2ffa246c449c533c41c 147356 libdbus-1-3_1.2.1-4_i386.deb
fb22eb9f932c2ef75db8c7533a8dbe2860626da3 234420 libdbus-1-dev_1.2.1-4_i386.deb
Checksums-Sha256:
af0e09cd8578c9069021306c3772039c1e3f71211d886dac6adbe79ba07876f2 1536 dbus_1.2.1-4.dsc
960ccc3821965de3d6af4bedcb8289058dc7105c4072623082a9f808068856d7 27997 dbus_1.2.1-4.diff.gz
c27edca261375c292b4d59718f6cbc0b56bfe4c60da288104a5294486e50c2a1 1819304 dbus-1-doc_1.2.1-4_all.deb
e0980eaa8523a31cd87b1435dc32f668b80a1b04cd87be2fafc8684146b2360f 226896 dbus_1.2.1-4_i386.deb
672f50e6d668ad0ceee30041b13a3c60dd1f98960f4c3b8f1c6e9c1976475201 63376 dbus-x11_1.2.1-4_i386.deb
8177472dc960b1f40aa814d8e7569c1ae0075fffd4e3574ebcd4e50d01d8a320 147356 libdbus-1-3_1.2.1-4_i386.deb
10d4ecb7e15c7dc6afa3d725a223d1681b251fcfa9d0dfa092c831fcb2694b65 234420 libdbus-1-dev_1.2.1-4_i386.deb
Files:
6d6daf14f915c633c79b80fa09d275b9 1536 devel optional dbus_1.2.1-4.dsc
cb4627493d5e1b3413f2a71d878f5498 27997 devel optional dbus_1.2.1-4.diff.gz
862f32a303238c6ba1189c3f18d40677 1819304 doc optional dbus-1-doc_1.2.1-4_all.deb
59de750c0db0f803f239e605e30929f0 226896 devel optional dbus_1.2.1-4_i386.deb
02345c5d82d75394ef54d97687c8f0cf 63376 x11 optional dbus-x11_1.2.1-4_i386.deb
9350602471beaf8c042547993c781112 147356 libs optional libdbus-1-3_1.2.1-4_i386.deb
e4e9391d9abe8f9cc0b0dc7657bd2c75 234420 libdevel optional libdbus-1-dev_1.2.1-4_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAkkDIm4ACgkQh7PER70FhVT4lwCaArKN4KEF5XE9NUvGCoLzjtK4
C4wAoKvpi33yLrhuQ+VxSY5MCc1uYK19
=a05U
-----END PGP SIGNATURE-----
Bug archived.
Request was from Debbugs Internal Request <owner@bugs.debian.org>
to internal_control@bugs.debian.org.
(Sun, 30 Nov 2008 07:33:51 GMT) (full text, mbox, link).
Debbugs is free software and licensed under the terms of the GNU General
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.