Package: imms
Version: 2.0.1-3
Severity: grave
File: /usr/bin/analyzer
Tags: security

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I was using analyzer on my music collection, and found this:

[EMAIL PROTECTED]:Claude Debussy$ analyzer 'Claude Debussy - Prelude "La Fille 
aux cheveux de lin".ogg';
sox: Can't open input file '/var/www/music/Maxwell/Classical/Claude 
Debussy/Claude Debussy - Prelude La': No such file or directory

A little work reveals this fun:

[EMAIL PROTECTED]:tmp$ touch '`echo $HOME`'
[EMAIL PROTECTED]:tmp$ analyzer '`echo $HOME`'
sox: Can't open input file '/tmp//home/anthony': No such file or directory

Considering how common playing files with untrusted names is (e.g., xmms
set as browser helper), this is quite a problem.

The problem is the popen on line 53 of analyzer.cc

- -- System Information:
Debian Release: 3.1
  APT prefers testing
  APT policy: (500, 'testing'), (130, 'unstable'), (120, 'experimental')
Architecture: i386 (i686)
Kernel: Linux 2.6.10-bohr
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)

Versions of packages imms depends on:
ii  fftw3                    3.0.1-11        Library for computing Fast Fourier
ii  libc6                    2.3.2.ds1-20    GNU C Library: Shared libraries an
ii  libgcc1                  1:3.4.3-6       GCC support library
ii  libglib1.2               1.2.10-9        The GLib library of C routines
ii  libglib2.0-0             2.6.1-2         The GLib library of C routines
ii  libgtk1.2                1.2.10-17       The GIMP Toolkit set of widgets fo
ii  libpcre3                 4.5-1.1         Perl 5 Compatible Regular Expressi
ii  libsqlite3-0             3.0.8-3         SQLite 3 shared library
ii  libstdc++5               1:3.3.5-5       The GNU Standard C++ Library v3
ii  libtag1                  1.3.1-1         TagLib Audio Meta-Data Library
ii  libx11-6                 4.3.0.dfsg.1-10 X Window System protocol client li
ii  libxext6                 4.3.0.dfsg.1-10 X Window System miscellaneous exte
ii  libxi6                   4.3.0.dfsg.1-10 X Window System Input extension li
ii  xlibs                    4.3.0.dfsg.1-10 X Keyboard Extension (XKB) configu
ii  xmms                     1.2.10-2        Versatile X audio player that look
ii  zlib1g                   1:1.2.2-3       compression library - runtime

- -- no debconf information

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFB+9+u+z+IwlXqWf4RAgVbAJwN1WeCkLAuouyDY9i36I2uvJNSXgCeOARs
COXsXScpCfAVi08DE7ZNBDY=
=Lplc
-----END PGP SIGNATURE-----


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to