tags 293110 -security
thanks

Its not a security hole unless the package maintainer is supposedly
trojaning the package such as to waste CPU.

This sounds like its potentially a window manager problem.  What WM
are you using?  I can't reproduce it here under blackbox; could you
also try another WM?

Justin

On Tue, Feb 01, 2005 at 02:18:25AM -0500, [EMAIL PROTECTED] wrote:
> 
> Package: kvim
> Version: 1:6.3-058+1
> Severity: grave
> Tags: security
> Justification: renders package unusable
> 
> 
> Everytime kvim is started, it automatically begins resizing itself in the
> horozontal direction. The package is therefore unusable by any user. CPU
> usage jumps to near 100% when kvim is opened, thus posing a possible
> security risk for the user.
> 
> 
> -- System Information:
> Debian Release: 3.1
>   APT prefers testing
>   APT policy: (500, 'testing')
> Architecture: i386 (i686)
> Kernel: Linux 2.6.8
> Locale: LANG=en_US, LC_CTYPE=en_US (charmap=ISO-8859-1)
> 
> Versions of packages kvim depends on:
> ii  kdelibs4                 4:3.3.2-1       KDE core libraries
> ii  libc6                    2.3.2.ds1-20    GNU C Library: Shared libraries 
> an
> ii  libgcc1                  1:3.4.3-6       GCC support library
> ii  libgpmg1                 1.19.6-19       General Purpose Mouse - shared 
> lib
> ii  libice6                  4.3.0.dfsg.1-10 Inter-Client Exchange library
> ii  libncurses5              5.4-4           Shared libraries for terminal 
> hand
> ii  libqt3c102-mt            3:3.3.3-7       Qt GUI Library (Threaded runtime 
> v
> ii  libsm6                   4.3.0.dfsg.1-10 X Window System Session 
> Management
> ii  libstdc++5               1:3.3.5-5       The GNU Standard C++ Library v3
> ii  libx11-6                 4.3.0.dfsg.1-10 X Window System protocol client 
> li
> ii  libxt6                   4.3.0.dfsg.1-10 X Toolkit Intrinsics
> ii  vim                      1:6.3-058+1     Vi IMproved - enhanced vi editor
> ii  xlibs                    4.3.0.dfsg.1-10 X Keyboard Extension (XKB) 
> configu


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to