Bug#463471: CVE-2008-0386 arbitrary code execution in xdg-utils via crafted path name

2008-02-01 Thread Per Olofsson
Nico Golde wrote: >> The code in question is not present in the Debian package, because I have >> patched it to use run-mailcap or sensible-browser instead. > [...] > Thanks, that looks secure to me. I missed the patch when > looking at the package because its name does not imply any > security

Bug#463471: CVE-2008-0386 arbitrary code execution in xdg-utils via crafted path name

2008-01-31 Thread Per Olofsson
Hi, Nico Golde wrote: > Source: xdg-utils > Severity: grave > Tags: security patch > > Hi, > the following CVE (Common Vulnerabilities & Exposures) id was > published for xdg-utils. The code in question is not present in the Debian package, because I have patched it to use run-mailcap or sensibl

Bug#463471: CVE-2008-0386 arbitrary code execution in xdg-utils via crafted path name

2008-01-31 Thread Nico Golde
Source: xdg-utils Severity: grave Tags: security patch Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for xdg-utils. CVE-2008-0386[0]: | Description of problem: | The generic handler of xdg-open (i.e. when not running in KDE, GNOME or XFCE) | has the following code: |