{"id":"MGASA-2026-0178","summary":"Updated xdg-dbus-proxy packages fix security vulnerability","details":"A policy parser vulnerability allows bypassing eavesdrop restrictions.\nThe proxy checks for eavesdrop=true in policy rules but fails to handle\neavesdrop ='true' (with a space before the equals sign) and similar\ncases.\n","modified":"2026-06-07T05:15:04.346641013Z","published":"2026-06-07T05:10:04Z","upstream":["CVE-2026-34080"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0178.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35347"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/04/10/15"},{"type":"ADVISORY","url":"https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-vjp5-hjfm-7677"}],"affected":[{"package":{"name":"xdg-dbus-proxy","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/xdg-dbus-proxy?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.7-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0178.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}