Bug#329156: /usr/sbin/gnome-pty-helper: writes arbitrary utmp records

Paul Szabo psz at maths.usyd.edu.au
Mon Sep 26 12:12:45 UTC 2005


Dear Loic,

>  Do you have a CVE ID for this security issue?

No. Sorry, I do not know how to get one. (Nor am sure if this is serious
enough to deserve one.)

>  Did you check whether libvte4 is affected?

No. Do not know what libvte4 is.

>  Do you have a fix?

No. (Fanciful idea: try running xhost, if it fails then surely you do not
"own" that display. Slow, maybe secure. That is what I use now.)

Cheers,

Paul Szabo   psz at maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia




More information about the Pkg-gnome-maintainers mailing list