Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Register
  • Sign in
  • G GLib
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 856
    • Issues 856
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 34
    • Merge requests 34
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Artifacts
    • Schedules
  • Deployments
    • Deployments
    • Releases
  • Packages and registries
    • Packages and registries
    • Container Registry
    • Model experiments
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • GNOMEGNOME
  • GLib
  • Issues
  • #2316
Closed
Open
Issue created Feb 03, 2021 by Philip Withnall@pwithnall🚫Maintainer

Re-harden DBUS_SESSION_BUS_ADDRESS for AT_SECURE processes in GLib 2.70

Revert !1920 (merged) for the GLib 2.70 cycle. See #2305 (closed) and !1920 (merged) for details; in particular this comment:

Along the principle of “if not now, when?”, I’ll merge this now for 2.68 (and backport to 2.66), but will also file an issue for reverting it for 2.70 (i.e. hardening GLib fully again). That should give gnome-keyring/libsecret and msmtp time to rework their security. Note that at this point any attacker has most of the information they need to likely be able to construct a vulnerability in msmtp, so fixing it should ideally be a priority for them. I’ll file issues against gnome-keyring and msmtp with the details and timeline.

Assignee
Assign to
Time tracking