[Pidgin] #15286: Master bug for old libraries in Windows Pidgin build

Pidgin trac at pidgin.im
Sun Aug 26 16:57:25 EDT 2012


#15286: Master bug for old libraries in Windows Pidgin build
----------------------+-----------------------------------------------------
 Reporter:  ioerror   |        Owner:  datallah       
     Type:  defect    |       Status:  new            
Milestone:            |    Component:  winpidgin (gtk)
  Version:  2.10.6    |   Resolution:                 
 Keywords:  security  |  
----------------------+-----------------------------------------------------

Comment(by ioerror):

 Replying to [comment:25 datallah]:
 > Replying to [comment:22 ioerror]:
 > > Replying to [comment:21 datallah]:
 > > > Yes, but the exception handler isn't used in this case, so we're
 still ok :)
 > > > See
 https://bitbucket.org/pidgin/main/src/release-2.x.y/pidgin/win32/winpidgin.c#cl-666
 > >
 > > When is that code ever used?
 >
 >
 [https://bitbucket.org/pidgin/main/src/release-2.x.y/pidgin/win32/winpidgin.c
 pidgin.exe] is effectively a launcher and has two basic purposes:
 >  * Set up the environment and launch the Pidgin GTK+ application
 >   * This is when exchndl.dll is loaded
 >  * Serve as a simple command line interface to pass messages into the
 currently running Pidgin instance.
 >   * This is the case above that the URI handlers use and exchndl.dll
 isn't used.

 OK. So, I'd say that fixing up exchndl.dll is probably worthwile, even if
 at the moment, we can't find an obvious way to trigger those bugs in an
 malicious manner. I'll move my discussion of that into #15289.

-- 
Ticket URL: <http://developer.pidgin.im/ticket/15286#comment:26>
Pidgin <http://pidgin.im>
Pidgin


More information about the Tracker mailing list