severity 462047 important
tag 462047 fixed-upstream
merge 462047 367956
thanks

On Tue, Jan 22, 2008 at 08:10:14AM +0100, Thomas Koenig wrote:
> Subject: iceweasel: crash/exploit
> Package: iceweasel
> Version: 2.0.0.11-1
> Severity: grave
> Justification: user security hole
> Tags: security
> 
> When browsing around web sites that I supposed were harmless
> (en.wikipedia.org, some newspaper websites) I got crashes, plus
> coredumps.  The next morning, I got a message from my ISP that my
> system had been used for sending out spam.

How can that be related ?

> After the fact, I installed iceweasel-dgb and ran gdb on the
> resulting corefile.  Output from a gdb session is included.

Your crash looks like a typical permission denied on a font file. See
bug #367956 and others.

Mike



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to