Bug#463471: CVE-2008-0386 arbitrary code execution in xdg-utils via crafted path name

2008-02-01 Thread Per Olofsson
Nico Golde wrote: The code in question is not present in the Debian package, because I have patched it to use run-mailcap or sensible-browser instead. [...] Thanks, that looks secure to me. I missed the patch when looking at the package because its name does not imply any security

Bug#463471: CVE-2008-0386 arbitrary code execution in xdg-utils via crafted path name

2008-01-31 Thread Nico Golde
Source: xdg-utils Severity: grave Tags: security patch Hi, the following CVE (Common Vulnerabilities Exposures) id was published for xdg-utils. CVE-2008-0386[0]: | Description of problem: | The generic handler of xdg-open (i.e. when not running in KDE, GNOME or XFCE) | has the following code: |

Bug#463471: CVE-2008-0386 arbitrary code execution in xdg-utils via crafted path name

2008-01-31 Thread Per Olofsson
Hi, Nico Golde wrote: Source: xdg-utils Severity: grave Tags: security patch Hi, the following CVE (Common Vulnerabilities Exposures) id was published for xdg-utils. The code in question is not present in the Debian package, because I have patched it to use run-mailcap or