[Pkg-xfce-devel] Bug#498770: Bug#498770: Bug#498770: Bug#498770: xfce4-mpc-plugin: Segfaults on mouseover after song change

Simon Huggins huggie at earth.li
Wed Nov 26 12:15:05 UTC 2008


On Tue, Nov 25, 2008 at 07:09:27PM -0500, Daniel Dickinson wrote:
> On Tue, 25 Nov 2008 09:09:29 +0000
> Simon Huggins <huggie at earth.li> wrote:
> > On Tue, Nov 25, 2008 at 02:06:04AM -0500, Daniel Dickinson wrote:
> > > On Mon, 6 Oct 2008 15:53:42 +0100
> > > Simon Huggins <huggie at earth.li> wrote:
> > > > I've put an i386 debug package at:
> > > > http://the.earth.li/~huggie/xfce4-mpc-plugin-debug/
> > > This crashes immediately after adding it, entering the connection
> > > information, and clicking close
> > Hmm, maybe there was something wrong with the package though I suppose
> > it might mean that there is a buffer overflow directly in the code
> > that deals with storing those settings.
> > How long are your connection settings/username/password etc?
> hostname is 6 chars + 8 char + .2char domain and the user I'm running
> as is also 6 chars.

> The password on the other hand is 27 characters long.

> *** test ****

> Okay, a shorter password clears up the problem.  It is definitely
> password length that is problem.

Aha.  Right, can you try the package at:
http://the.earth.li/~huggie/xfce4-mpc-plugin_0.3.3-1huggie_i386.deb

I'll file a bug with upstream tonight but there's a fairly obvious
buffer overflow in mpd_send_password.

-- 
 _        huggie at earth.li      -+*+-     fou, con et anglais      _
(_)   "No one - no government agency has jurisdiction over the   (_)
(_)                       truth." - Mulder                       (_)
  \___                                                        ___/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://lists.alioth.debian.org/pipermail/pkg-xfce-devel/attachments/20081126/9db5c6d7/attachment.pgp 


More information about the Pkg-xfce-devel mailing list