nixpkgs/pkgs
Will Dietz 6d7cdd7f8b dbus: 1.12.14 -> 1.12.16
https://gitlab.freedesktop.org/dbus/dbus/blob/dbus-1.12.16/NEWS

It's short and explains the CVE a bit, including below:

> CVE-2019-12749: Do not attempt to carry out DBUS_COOKIE_SHA1
> authentication for identities that differ from the user running the
> DBusServer. Previously, a local attacker could manipulate symbolic
> links in their own home directory to bypass authentication and connect
> to a DBusServer with elevated privileges. The standard system and
> session dbus-daemons in their default configuration were immune to this
> attack because they did not allow DBUS_COOKIE_SHA1, but third-party
> users of DBusServer such as Upstart could be vulnerable.   Thanks to Joe
> Vennix of Apple Information Security.   (dbus#269, Simon McVittie)
2019-06-15 18:16:58 +02:00
..
applications Merge pull request #63107 from eadwu/vscode/1.35.1 2019-06-14 16:13:35 -04:00
build-support Merge branch 'master' into staging-next 2019-06-14 17:47:23 +02:00
common-updater common-updater-scripts: simplify fetchgit fix 2019-06-02 09:31:51 +02:00
data all-cabal-hashes: update to Hackage at 2019-06-14T00:22:02Z 2019-06-14 13:06:35 +00:00
desktops pantheon.wingpanel-applications-menu: drop libwnck3 2019-06-15 03:50:18 -04:00
development dbus: 1.12.14 -> 1.12.16 2019-06-15 18:16:58 +02:00
games dwarf-fortress-packages.dwarf-therapist-original: expose to package set 2019-06-10 18:52:52 +03:00
misc vimPlugins: update (#63119) 2019-06-14 12:13:50 +02:00
os-specific Merge master into staging-next 2019-06-15 08:17:58 +02:00
servers Merge branch 'master' into staging-next 2019-06-14 17:47:23 +02:00
shells oh-my-zsh: 2019-06-11 -> 2019-06-12 2019-06-13 10:06:36 -04:00
stdenv Merge branch 'master' into staging-next 2019-06-05 11:06:44 +02:00
test all-packages/test: add gcc9Stdenv, cc-wrapper-gcc9 2019-05-07 17:21:31 -05:00
tools ddar: fix build 2019-06-15 10:06:54 +02:00
top-level python: llvmlite: 0.28.0 -> 0.29.0 2019-06-15 09:43:09 +02:00