From 4f2d7949f03e1c198bc888f2d05f421d35c57e21 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 9 Oct 2017 18:53:29 +0100 Subject: reinit the tree, so we can have metadata --- metadata/glsa/glsa-201402-27.xml | 51 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 51 insertions(+) create mode 100644 metadata/glsa/glsa-201402-27.xml (limited to 'metadata/glsa/glsa-201402-27.xml') diff --git a/metadata/glsa/glsa-201402-27.xml b/metadata/glsa/glsa-201402-27.xml new file mode 100644 index 000000000000..b6367069fafb --- /dev/null +++ b/metadata/glsa/glsa-201402-27.xml @@ -0,0 +1,51 @@ + + + + pidgin-knotify: Arbitrary code execution + A vulnerability in pidgin-knotify might allow remote attackers to + execute arbitrary code. + + pidgin-knotify + 2014-02-26 + 2014-02-26: 1 + 336916 + remote + + + 0.2.1 + + + +

pidgin-knotify is a Pidgin plug-in to display message notifications in + KDE. +

+
+ +

pidgin-knotify does not properly sanitize shell metacharacters from + received messages. +

+
+ +

A remote attacker could send a specially crafted instant message, + possibly resulting in execution of arbitrary code with the privileges of + the Pidgin process. +

+
+ +

There is no known workaround at this time.

+
+ +

Gentoo has discontinued support for pidgin-knotify. We recommend that + users unmerge pidgin-knotify: +

+ + + # emerge --unmerge "x11-plugins/pidgin-knotify" + +
+ + CVE-2010-3088 + + ackle + ackle +
-- cgit v1.2.3