[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#591511: Bug#581194: libpoe-component-irc-perl: Insufficient stripping of CR/LF allows arbitrary IRC command execution



On Tue, 03 Aug 2010 15:45:22 -0400, Adam D. Barratt wrote:

> > I contacted upstream on IRC before preparing the package because I was a
> > bit unsure about this part as well and they confirmed that including
> > only
> >
> > +    # if we find a newline in the message, take that to be the end of it
> > +    $msg =~ s/[\015\012].*//s;
> >
> > should be enough to fix the issue.
> Thanks for the explanation; please go ahead with the upload.

Thanks to both of you; uploaded.

Cheers,
gregor

-- 
 .''`.   http://info.comodo.priv.at/ -- GPG key IDs: 0x8649AA06, 0x00F3CFE4
 : :' :  Debian GNU/Linux user, admin, & developer - http://www.debian.org/
 `. `'   Member of VIBE!AT & SPI, fellow of Free Software Foundation Europe
   `-    BOFH excuse #296:  The hardware bus needs a new token. 

Attachment: signature.asc
Description: Digital signature


Reply to: