Bug#510636: libosso: Has a dbus config file which circumvents all security messages on the system bus

Matthew Johnson mjj29 at debian.org
Sun Jan 4 15:05:07 UTC 2009


On Sun Jan 04 16:37, Riku Voipio wrote:
> On Sat, Jan 03, 2009 at 10:53:08PM +0000, Matthew Johnson wrote:
> > libosso1 ships /etc/dbus-1/system.d/libosso.conf which turns off all the
> > security checks on the system bus by allowing all messages from everyone
> > to everyone else. This is bad mkay?
> 
> I believe this kind of open dbus communication is not needed by any
> of the maemo apps in debian, so we can just drop the conffile.

You will also need to ensure that they all have the appropriate config
file to work with the fixed version of DBus (either try the one in
experimental which has this fix or we will soon make available the
version which will be uploaded to unstable/testing).

Matt

-- 
Matthew Johnson
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://lists.alioth.debian.org/pipermail/pkg-maemo-maintainers/attachments/20090104/fdb2aef0/attachment.pgp 


More information about the pkg-maemo-maintainers mailing list