Copied from
debian sid in
Primary Archive for Debian GNU/Linux
Changelog
gvfs (1.38.1-5) unstable; urgency=high
* Team upload
* d/p/gvfsdaemon-Check-that-the-connecting-client-is-the-same-u.patch:
Add missing authentication, preventing a local attacker from connecting
to an abstract socket address learned from netstat(8) and issuing
arbitrary D-Bus method calls
* d/p/gvfsdaemon-Only-accept-EXTERNAL-authentication.patch:
Harden private D-Bus connection by rejecting the more complicated
DBUS_COOKIE_SHA1 authentication mechanism and only accepting EXTERNAL.
-- Simon McVittie <email address hidden> Tue, 11 Jun 2019 12:28:34 +0100