Re: [Bug 311983] Re: Window title, DECRQSS security

2009-12-12 Thread Thomas Dickey
On Sat, 12 Dec 2009, Paul Szabo wrote: xterm can't change it's title any more. ... ... look at the control-right-mouse entry for Enable Title Ops ... Testing my own karmic machine: the xterm default Allow Title Ops is ticked, Allow Window Ops is not ticked. Apparently regardless of

Re: [Bug 311983] Re: Window title, DECRQSS security

2009-12-12 Thread Paul Szabo
Dear Thomas, The problem is not with the meanings or descriptions of AllowTitleOps (though a warning that setting AllowWindowOps is insecure is missing). The problem is that perl -e 'print \e\]0;;bad-command;\a\e\[21t' should set the title (then maybe retrieve it); but that setting does not

Re: [Bug 311983] Re: Window title, DECRQSS security

2009-12-12 Thread Thomas Dickey
On Sat, 12 Dec 2009, Paul Szabo wrote: Dear Thomas, The problem is not with the meanings or descriptions of AllowTitleOps (though a warning that setting AllowWindowOps is insecure is missing). The problem is that perl -e 'print \e\]0;;bad-command;\a\e\[21t' should set the title (then

[Bug 311983] Re: Window title, DECRQSS security

2009-12-12 Thread David Sharnoff
Sorry, I'm using 243-1ubuntu1 -- the current version in Karmic. -- Window title, DECRQSS security https://bugs.launchpad.net/bugs/311983 You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. -- ubuntu-bugs mailing list

Re: [Bug 311983] Re: Window title, DECRQSS security

2009-12-12 Thread Thomas Dickey
On Sat, 12 Dec 2009, David Sharnoff wrote: Sorry, I'm using 243-1ubuntu1 -- the current version in Karmic. thanks (I don't have Ubuntu, so I need information to fill in between upstream source and the package details). -- Thomas E. Dickey http://invisible-island.net ftp://invisible-island.net

[Bug 311983] Re: Window title, DECRQSS security

2009-12-11 Thread David Sharnoff
xterm can't change it's title any more. Did this fixing this bug break this important feature? The screen program is one example of an application where changing the title critical. Title changes still work with gnome. Only broken with kde. Karmic. -- Window title, DECRQSS security

Re: [Bug 311983] Re: Window title, DECRQSS security

2009-12-11 Thread Thomas Dickey
On Sat, 12 Dec 2009, David Sharnoff wrote: xterm can't change it's title any more. Did this fixing this bug There is a resource setting that can disable it - perhaps someone set that. (which version of xterm are we discussing?) break this important feature? The screen program is one

Re: [Bug 311983] Re: Window title, DECRQSS security

2009-12-11 Thread Paul Szabo
xterm can't change it's title any more. ... ... look at the control-right-mouse entry for Enable Title Ops ... Testing my own karmic machine: the xterm default Allow Title Ops is ticked, Allow Window Ops is not ticked. Apparently regardless of setting, using perl -e 'print

[Bug 311983] Re: Window title, DECRQSS security

2009-01-05 Thread Kees Cook
** Changed in: xterm (Ubuntu) Importance: Undecided = Medium Assignee: (unassigned) = Kees Cook (kees) Status: New = Fix Committed -- Window title, DECRQSS security https://bugs.launchpad.net/bugs/311983 You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 311983] Re: Window title, DECRQSS security

2009-01-05 Thread Launchpad Bug Tracker
This bug was fixed in the package xterm - 235-1ubuntu1.1 --- xterm (235-1ubuntu1.1) intrepid-security; urgency=low * SECURITY UPDATE: command injection via dangerous terminal sequences (CVE-2008-2383, LP: #311983). - block DECRQSS, font shifting, X property changes,

[Bug 311983] Re: Window title, DECRQSS security

2008-12-28 Thread Paul Szabo
** Visibility changed to: Public -- Window title, DECRQSS security https://bugs.launchpad.net/bugs/311983 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com