kde 4.4.80-1 & 4.4.85

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Thomas Janssen wrote:
> Ah, thanks. I did just recall the stream analyzer problem, but didn't
> know what exactly happened. That explains it.

Of course, the fact that the GZip analyzer crashed on the (from its POV) 
invalid input is a bad sign, this appears to be a DoS vulnerability or 
worse.

Strigi analyzers seem quite crash-prone to me, not very confidence-inspiring 
for something which can run on untrusted (e.g. downloaded from some web 
page) files.

        Kevin Kofler



[Index of Archives]     [KDE Users]     [Fedora General Discussion]     [Older Fedora Users Mail]     [Fedora Advisory Board]     [Fedora Security]     [Fedora Maintainers]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [ATA RAID]     [Fedora Marketing]     [Fedora Mentors]     [Fedora Package Announce]     [Fedora Package Review]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Triage]     [Coolkey]     [Yum Users]     [Yosemite Forum]     [Fedora Art]     [Fedora Docs]     [Asterisk PBX]

  Powered by Linux