Pidgin denial of service with invalid gifs

Mark Doliner mark at kingant.net
Sun Jun 12 23:33:43 EDT 2011


Ok, great, thanks!  Just wanted to make sure I'm not imagining this whole thing.

I got a response from Matthias Clasen from Gnome.  He proposed a patch
to gdk pixbuf and cc'ed the Red Hat security team for "evaluation on
the severity and embargo considerations."  But I haven't heard
anything from them since then (like two weeks ago).  I'll try to send
a proposed patch to this list later tonight to see what you guys
think, and I'll try to poke Gnome/Red Hat on their thoughts about an
embargo.

--Mark


More information about the security mailing list