remote crasher in the IRC WHO changes

Paul Aurich paul at darkrain42.org
Tue Jul 12 23:40:06 EDT 2011


On 2011-07-11 09:23, Ethan Blanton wrote:
> Ethan Blanton spake unto us the following wisdom:
>> xnyhps with Adium pointed out that I forgot to fixup the final
>> :argument.  A fixed patch is here:
>>
>>     http://pidgin.im/~elb/private/irc_who_fix-2.diff
> 
> Paul, any chance you've had a chance to verify this fix?

I can confirm this patch works using the channel info provided by mesb
(http://developer.pidgin.im/ticket/14341#comment:15).

It's worthy of note that this *does not* crash under Linux (Debian Sid)
[I got malformed UTF8 messages in the debug log, but no crash], but does
under Windows and with Adium 1.4.3b1.

> I really want to 1) make sure this fix goes into 2.9.1, 2) have this
> vetted in time to send to packagers@ and get a CVE before 2.9.1, and
> 3) get 2.9.1 out relatively soon.

Aye, this sounds like a good plan.

~Paul

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 897 bytes
Desc: OpenPGP digital signature
URL: <http://pidgin.im/cgi-bin/mailman/private/security/attachments/20110712/49a7d283/attachment.pgp>


More information about the security mailing list