severity 462047 important tag 462047 fixed-upstream merge 462047 367956 thanks
On Tue, Jan 22, 2008 at 08:10:14AM +0100, Thomas Koenig wrote: > Subject: iceweasel: crash/exploit > Package: iceweasel > Version: 2.0.0.11-1 > Severity: grave > Justification: user security hole > Tags: security > > When browsing around web sites that I supposed were harmless > (en.wikipedia.org, some newspaper websites) I got crashes, plus > coredumps. The next morning, I got a message from my ISP that my > system had been used for sending out spam. How can that be related ? > After the fact, I installed iceweasel-dgb and ran gdb on the > resulting corefile. Output from a gdb session is included. Your crash looks like a typical permission denied on a font file. See bug #367956 and others. Mike -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

