Bug#608981: Crash with long GGI_DISPLAY environment variable

2012-08-10 Thread Jonathan Wiltshire
Package: libggi Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0.6) -

Bug#608981: Crash with long GGI_DISPLAY environment variable

2012-07-06 Thread Moritz Mühlenhoff
On Mon, Jan 17, 2011 at 12:27:15AM +0100, Julien Cristau wrote: user release.debian@packages.debian.org usertag 608981 squeeze-can-defer tag 608981 squeeze-ignore kthxbye On Fri, Jan 14, 2011 at 23:35:48 +0100, Moritz Mühlenhoff wrote: reassign 608981 libggi2 thanks On Wed,

Bug#608981: Crash with long GGI_DISPLAY environment variable

2011-01-16 Thread Julien Cristau
user release.debian@packages.debian.org usertag 608981 squeeze-can-defer tag 608981 squeeze-ignore kthxbye On Fri, Jan 14, 2011 at 23:35:48 +0100, Moritz Mühlenhoff wrote: reassign 608981 libggi2 thanks On Wed, Jan 05, 2011 at 04:16:36PM +1100, Silvio Cesare wrote: Package: zhcon

Bug#608981: Crash with long GGI_DISPLAY environment variable

2011-01-04 Thread Silvio Cesare
Package: zhcon Version: 1:0.2.6-5.2 Severity: important Tags: security zhcon crashes when a long GGI_DISPLAY environment variable is used with ggi. Probably indicative of a buffer overflow. zhcon is SUID root, so this crash might potentially lead to privilege escalation. I haven't investigated