recommended D-Bus version for GNOME releases



Hi guys,

I was going over the GNOME release and noticed we are still using 0.93.
Not only is this a non supported version upstream it contains a denial
of service exploit CVE-2006-6107 - match rules can be removed by apps
that did not create them.  I suggest we move recommendations to 1.0.2
which fixes that bug and a whole lot of other bugs.  1.0.x series is
API/ABI stable and supported by upstream.

-- 
John (J5) Palmieri <johnp redhat com>




[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]