LWN.net Logo

Remote arbitrary code execution vulnerability in gaim

Remote arbitrary code execution vulnerability in gaim

Posted Aug 29, 2002 1:44 UTC (Thu) by robot101 (subscriber, #3479)
Parent article: Remote arbitrary code execution vulnerability in gaim

Oops. I must apologise here, I wrote some of that text when outlining the problem to the Debian security team. Gaim does actually give you a tooltip of the URL. Furthermore, Chris Blizzard from RedHat found that whilst my patch fixed the issue for the manual browser command, it erroneously made the other browser commands use unallocated memory, which could cause a crash (but after forking, would just result in the URL not being shown, and maybe a core file =). This is fixed for Debian in 0.59.1-3 in sid, and 0.58-2.3 in woody. See here for the patch.


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds