[Debian-audit] Six more + gpsd

From: Ulf Härnhammar <Ulf.Harnhammar.9485_at_student.uu.se>
Date: Wed, 26 Jan 2005 23:58:03 +0100

Hello,

I have a bunch of new Debian bugs:

http://bugs.debian.org/290822 (billard-gl)
http://bugs.debian.org/291613 (xshisen again.. aaarghh!)
http://bugs.debian.org/291620 (ltris)
http://bugs.debian.org/291635 (man2html)
http://bugs.debian.org/292263 (scummvm)
http://bugs.debian.org/292264 (penguin-command)

I can officially say that fscanf(fp, "%s", buf); has
replaced sprintf(buf, "%s/blah", getenv("HOME")); as
my biggest hate object.

Joey Hess has found even more security problems with xshisen
(#292065), so people are debating removing the gid-ness from
that nice game.

KF found my format string bug in gpsd (#292370)! I can't prove
it, but I really found that bug too some time ago. I meant to
audit the rest of gpsd (bad idea?), but I didn't for some
reason, and now he's found it too and made it public. Oh well.

-- 
Ulf Harnhammar
http://www.advogato.org/person/metaur/
Received on Wed Jan 26 2005 - 22:58:13 GMT

Mailing list overview.