Search Members Help

» Welcome Guest
[ Log In :: Register ]

Mini-ITX Boards Sale, Fanless BareBones Mini-ITX, Bootable 1G DSL USBs, 533MHz Fanless PC <-- SALE $200 each!
Get The Official Damn Small Linux Book. DSL Market , Great VPS hosting provided by Tektonic
 

[ Track this topic :: Email this topic :: Print this topic ]

reply to topic new topic new poll
Topic: Security issue with ZXGV< Next Oldest | Next Newest >
WoofyDugfock Offline





Group: Members
Posts: 146
Joined: Sep. 2004
Posted: May 31 2005,09:09 QUOTE

I was just looking at the XZGV website. The author has posted the following warning about versions 0.8 and before (dsl has 0.7):

Quote
WARNING: There is a known vulnerability in xzgv 0.8 (and all previous versions) such that suitably-constructed images can be made to run arbitrary commands (as the user) when viewed with xzgv. This has the potential to cause serious trouble, so I strongly recommend applying this patch (with e.g. "patch -p0 <xzgv*.diff") before compiling. This is intended as a temporary measure until I can put together a more comprehensive fix (which would be complicated and isn't likely to happen soon), but should be effective in the meantime.


I don't know if this has been brought up before (didn't see it on a quick search).  Should this perhaps be fixed in future versions of dsl?

Or: maybe someone might point me at a how-to for applying the author's patch to dsl.


--------------
"We don't need no stinkin' Windows"

http://news.zdnet.co.uk/software/linuxunix/0,39020390,39149796,00.htm
Back to top
Profile PM 
WoofyDugfock Offline





Group: Members
Posts: 146
Joined: Sep. 2004
Posted: June 15 2005,11:57 QUOTE

I'm pleased to see a patch has now been applied in dsl 1.2.1 - though my post wasn't replied to?

Not that it's a big deal, it's just that it is nice to know whether or not one has contributed by flagging something ....


--------------
"We don't need no stinkin' Windows"

http://news.zdnet.co.uk/software/linuxunix/0,39020390,39149796,00.htm
Back to top
Profile PM 
WoofyDugfock Offline





Group: Members
Posts: 146
Joined: Sep. 2004
Posted: June 18 2005,14:00 QUOTE

Hush my big fat mouth - it WAS acknowledged ...

here

Just as well I didn't get all pouty!  :p


--------------
"We don't need no stinkin' Windows"

http://news.zdnet.co.uk/software/linuxunix/0,39020390,39149796,00.htm
Back to top
Profile PM 
2 replies since May 31 2005,09:09 < Next Oldest | Next Newest >

[ Track this topic :: Email this topic :: Print this topic ]

 
reply to topic new topic new poll
Quick Reply: Security issue with ZXGV

Do you wish to enable your signature for this post?
Do you wish to enable emoticons for this post?
Track this topic
View All Emoticons
View iB Code