[Pidgin] #2216: Vulnerability in Pidgin 2.0.2 - remote authenticated to execute commands

Pidgin trac at pidgin.im
Sat Jul 21 00:08:52 EDT 2007


#2216: Vulnerability in Pidgin 2.0.2 - remote authenticated to execute commands
----------------------------------+-----------------------------------------
  Reporter:  pr0gm3r              |       Owner:  sadrul                          
      Type:  defect               |      Status:  new                             
  Priority:  minor                |   Milestone:                                  
 Component:  finch (gnt/ncurses)  |     Version:  2.0.2                           
Resolution:                       |    Keywords:  vulnerability, exploit, security
   Pending:  0                    |  
----------------------------------+-----------------------------------------
Comment (by MarkDoliner):

 For the record I think Wabisabilabi Ltd. is fucking ridiculous.  As a
 Pidgin developer I volunteer a lot of my free time to contribute to
 something that I think benefits many other people.

 And rather than helping us, Wabisabilabi Ltd. tries to make money off of
 flaws in our product.  They are, in essence, holding information hostage
 from us, while offering the information to people who may have malicious
 intent.

 I'd be less pissed off if they disclosed the security problem to us
 privately and free of charge, but then also offered to sell the
 information to interested parties.

-- 
Ticket URL: <http://developer.pidgin.im/ticket/2216#comment:2>
Pidgin <http://pidgin.im>
Pidgin


More information about the Tracker mailing list