LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Slackware (https://www.linuxquestions.org/questions/slackware-14/)
-   -   [BUG] vte (https://www.linuxquestions.org/questions/slackware-14/%5Bbug%5D-vte-4175420249/)

mancha 08-03-2012 03:57 PM

[BUG] vte
 
1 Attachment(s)
vte, as packaged by Slackware through -current, has a bug which allows for a local DoS. Any program built against libvte (such as mosh or Xfce's Terminal) is vulnerable. Upstream corrected this starting with vte 0.32+ so I backported the fix for Slackware and provided Pat a copy.

To test, open Xfce's Terminal (/usr/bin/Terminal) and type:

Code:

echo -en "\e[9999999999P"
Watch your CPU go crazy in conky or gkrellm. /bin/kill that terminal to stop the madness.

An official Slackware patch is probably forthcoming. However, for the impatient among us, here's my fix. Just apply it to vte and rebuild.

-mancha

mancha 08-04-2012 06:19 AM

It wasn't clear in my last post that this patch applies against vte 0.28.x (as in -current). If demand exists, I guess I could work on patches back to 13.37 or maybe 13.1.

-mancha


All times are GMT -5. The time now is 10:32 AM.