2007-02-25 20:17:24 |
Reinhard Tartler |
bug |
|
|
added bug |
2007-02-25 20:17:51 |
Reinhard Tartler |
bug |
|
|
added subscriber Darren Salt |
2007-02-25 20:18:02 |
Reinhard Tartler |
bug |
|
|
added subscriber MOTU Media Team |
2007-02-27 20:15:06 |
Kees Cook |
bug |
|
|
added subscriber MOTU SWAT Team |
2007-02-27 20:16:29 |
Kees Cook |
gxine: status |
Unconfirmed |
Rejected |
|
2007-02-27 20:16:29 |
Kees Cook |
gxine: statusexplanation |
|
This is fixed in feisty (was fixed in gxine 0.5.10, it seems). Opening edgy and dapper tasks... |
|
2007-02-27 20:16:53 |
Kees Cook |
gxine: status |
Unconfirmed |
Confirmed |
|
2007-02-27 20:16:53 |
Kees Cook |
gxine: statusexplanation |
|
|
|
2007-02-27 20:17:09 |
Kees Cook |
gxine: status |
Unconfirmed |
Confirmed |
|
2007-02-27 20:17:09 |
Kees Cook |
gxine: statusexplanation |
|
|
|
2007-03-10 23:39:56 |
William Grant |
gxine: status |
Confirmed |
In Progress |
|
2007-03-10 23:39:56 |
William Grant |
gxine: assignee |
|
fujitsu |
|
2007-03-10 23:39:56 |
William Grant |
gxine: statusexplanation |
|
I have a debdiff for Dapper prepared. gxine is in main for Edgy. |
|
2007-03-11 00:07:46 |
William Grant |
bug |
|
|
added attachment 'gxine_0.5.1-0ubuntu15.1.diff' (debdiff for dapper-security) |
2007-03-12 20:17:26 |
Kees Cook |
gxine: importance |
Undecided |
Low |
|
2007-03-12 20:19:29 |
Kees Cook |
gxine: importance |
Undecided |
Low |
|
2007-03-12 20:19:29 |
Kees Cook |
gxine: statusexplanation |
I have a debdiff for Dapper prepared. gxine is in main for Edgy. |
Thanks for getting the debdiff prepared. After examining the code, I don't think I'm going to issue a security update for this flaw; it doesn't appear to be exploitable. If someone can prove me wrong, please do. From what I can see, a user can just overflow themselves, making this just a regular bug. |
|
2007-03-12 20:19:57 |
Kees Cook |
title |
Multiple buffer overflows |
overflow with long HOME environment variable |
|
2007-04-02 06:44:24 |
William Grant |
gxine: status |
In Progress |
Rejected |
|
2007-04-02 06:44:24 |
William Grant |
gxine: statusexplanation |
Thanks for getting the debdiff prepared. After examining the code, I don't think I'm going to issue a security update for this flaw; it doesn't appear to be exploitable. If someone can prove me wrong, please do. From what I can see, a user can just overflow themselves, making this just a regular bug. |
|
|
2007-04-02 06:44:52 |
William Grant |
gxine: status |
Confirmed |
Rejected |
|