dbus/doc
Havoc Pennington 7d65a3a6ed CVE 2010-4352: Reject deeply nested variants
Add DBUS_INVALID_NESTED_TOO_DEEPLY validity problem and a test that
should generate it.

Previously, we rejected deep nesting in the signature, but
variants allow dynamic message nesting, conditional only
on the depth of the message body.

The nesting limit is 64, which was also the limit in static
signatures.  Empirically, dynamic nesting depth observed on my
Fedora 14 system doesn't exceed 2; 64 is really a huge limit.

https://bugs.freedesktop.org/show_bug.cgi?id=32321

Signed-Off-By: Colin Walters <walters@verbum.org>
Signed-off-by: Will Thompson <will.thompson@collabora.co.uk>
2010-12-20 21:39:00 +00:00
..
.gitignore Move uploading docs into build system. 2010-10-05 11:46:00 +01:00
busconfig.dtd Bug 18446: Keep umask for session bus 2009-01-06 18:20:13 -05:00
dbus-cleanup-sockets.1 Move manpages to doc/ 2010-10-05 11:45:59 +01:00
dbus-daemon.1.in Move manpages to doc/ 2010-10-05 11:45:59 +01:00
dbus-faq.xml 2006-11-17 Havoc Pennington <hp@redhat.com> 2006-11-18 03:21:50 +00:00
dbus-launch.1 Move manpages to doc/ 2010-10-05 11:45:59 +01:00
dbus-monitor.1 Move manpages to doc/ 2010-10-05 11:45:59 +01:00
dbus-send.1 Move manpages to doc/ 2010-10-05 11:45:59 +01:00
dbus-specification.xml CVE 2010-4352: Reject deeply nested variants 2010-12-20 21:39:00 +00:00
dbus-test-plan.xml * s/D-BUS/D-Bus/g 2006-08-03 20:34:36 +00:00
dbus-tutorial.xml * doc/dbus-tutorial.xml: Replace Python section of tutorial with 2007-01-25 16:42:54 +00:00
dbus-uuidgen.1 Move manpages to doc/ 2010-10-05 11:45:59 +01:00
dcop-howto.txt initial import of "dbus" skeleton 2002-11-21 16:41:33 +00:00
diagram.png 2005-01-18 Havoc Pennington <hp@redhat.com> 2005-01-18 20:42:15 +00:00
diagram.svg 2005-01-18 Havoc Pennington <hp@redhat.com> 2005-01-18 20:42:15 +00:00
file-boilerplate.c Bug 21161 - Update the FSF address 2009-07-14 15:39:47 -04:00
introspect.dtd * s/D-BUS/D-Bus/g 2006-08-03 20:34:36 +00:00
introspect.xsl Bug 21161 - Update the FSF address 2009-07-14 15:39:47 -04:00
Makefile.am Move uploading docs into build system. 2010-10-05 11:46:00 +01:00
system-activation.txt 2007-07-24 Richard Hughes <richard@hughsie.com> 2007-07-24 11:23:46 +00:00
TODO 2006-11-08 Havoc Pennington <hp@redhat.com> 2006-11-09 00:19:29 +00:00