Package: Xdialog
Version: 2.0.6-3
Severity: critical
Justification: breaks the whole system

Running
    Xdialog --menubox "rotation angle?" 0 0 0 \
        ""  "erase picture" \
        0   "don't rotate" \
        90  "clockwise" \
        180 "flip over" \
        270 "anticlock"
makes the "erase picture" option grayed out.  If I click on it, my
system becomes unresponsive for five minutes while all 2.5 GB
memory+swap are allocated.  However, the crash is a segfault rather
than "memory exhausted."

If the option is " " rather than "" there is no problem.

Trivial input sanitization is in order here.

Rob

-- System Information:
Debian Release: 3.1
  APT prefers testing
  APT policy: (985, 'testing'), (30, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.4.26
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)

Versions of packages Xdialog depends on:
ii  libc6              2.3.2.ds1-22          GNU C Library: Shared libraries an
ii  libglib1.2         1.2.10-9              The GLib library of C routines
ii  libgtk1.2          1.2.10-17             The GIMP Toolkit set of widgets fo
ii  xlibs              4.3.0.dfsg.1-14sarge1 X Keyboard Extension (XKB) configu

-- no debconf information

-- 
Rob Mahurin
Dept. of Physics & Astronomy    phone:  865.974.8097 (sometimes)
University of Tennessee         fax:    865.974.7843
Knoxville, TN  37996            email:  [EMAIL PROTECTED]
--
As well look for a needle in a bottle of hay.
                -- Miguel de Cervantes


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to