* Mike Hommey:

> If you think a bare crash needs severity grave, then please go ahead
> and raise severity of

Most of these bugs are not exploitable, i.e. an attacker cannot use
them to deliberately cause data loss.

> #270822, 

Not reproducible, non-standard configuration, not exploitable.

> #274527,

Cannot be triggered by an attacker (it seems).

> #289409,

Very non-standard miscconfiguration, not exploitable.

> #289608, 

Bug is in another package (Flash plugin).

> #294428, 

Probably a CUPS bug.  Misconfiguration, not exploitable.

> #298703, 

Misconfiguration, not exploitable.

> #298298,

Seems to be completely unrelated.

> #307350, 

Not reproducible, apparently not known to be exploitable.

> #309931,

This one seems to be real, and it might be automatically exploitable
(needs more investigation).

> #313291,

Not reproducible, probably plugin bug.

> #320553,

Looks like the user installs broken software.  Doesn't seem to be a
bug in one of our packages.

> #324791, 

OS crash required.  Arguably a bug, but not exploitable.

> #330396,

This one looks exploitable indeed.

> #331673, 

Uhm, exploitable.

> #334654, 

Exploitable.

> #335708,

Exploitable.

> #336411, 

Not exploitable, user installs incompatible plugins.

> #276393, 

Doesn't crash for me anymore with 1.0.7-1.

> #281788, 

Unclear.

> #309325

Not exploitable, happens on browser start.

> and #331329.

Not reproducible for me, page renders for me.

So the situation isn't as bad as you indicated.  There are only five
crash triggers, some of them potential dupes.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to