remote crasher in the IRC WHO changes

Ethan Blanton elb at pidgin.im
Mon Jul 11 12:23:11 EDT 2011


Ethan Blanton spake unto us the following wisdom:
> Ethan Blanton spake unto us the following wisdom:
> > A patch which I believe fixes the WHO parsing errors is available from:
> > 
> >     http://pidgin.im/~elb/private/irc_who_fix.diff
> > 
> > I suspect we want to embargo this for 2.9.1.
> 
> xnyhps with Adium pointed out that I forgot to fixup the final
> :argument.  A fixed patch is here:
> 
>     http://pidgin.im/~elb/private/irc_who_fix-2.diff

Paul, any chance you've had a chance to verify this fix?

Adium people, you caused this problem, have you had a chance to check
that the fix works for Adium?

I really want to 1) make sure this fix goes into 2.9.1, 2) have this
vetted in time to send to packagers@ and get a CVE before 2.9.1, and
3) get 2.9.1 out relatively soon.

Ethan


More information about the security mailing list