Bug#405876: Subject: gxine: segfault on startup with long HOME dir

2007-01-09 Thread Steve Langasek
Hi Darren, On Sun, Jan 07, 2007 at 03:24:49AM +, Darren Salt wrote: I demand that Florian Grunow may or may not have written... Debian gxine uses the HOME environment variable without proper bounds checking in version 0.5.8. This results in a buffer overflow when the HOME environment

Bug#405876: Subject: gxine: segfault on startup with long HOME dir

2007-01-09 Thread Darren Salt
I demand that Steve Langasek may or may not have written... On Sun, Jan 07, 2007 at 03:24:49AM +, Darren Salt wrote: [snip] I'll prepare a 0.5.8 update with [the fix for the segfault], but I'd like to know (from an RM's point of view) which of the patches in the existing 0.5.8-2 should

Bug#405876: Subject: gxine: segfault on startup with long HOME dir

2007-01-06 Thread Florian Grunow
Package: gxine Version: 0.5.8-1 Severity: important Debian gxine uses the HOME environment variable without proper bounds checking in version 0.5.8. This results in a buffer overflow when the HOME environment variable is longer than or equal to 242. It is possible to execute code, which doesn't

Bug#405876: Subject: gxine: segfault on startup with long HOME dir

2007-01-06 Thread Darren Salt
I demand that Florian Grunow may or may not have written... Debian gxine uses the HOME environment variable without proper bounds checking in version 0.5.8. This results in a buffer overflow when the HOME environment variable is longer than or equal to 242. It is possible to execute code,