On Tue, Nov 25, 2008 at 07:09:27PM -0500, Daniel Dickinson wrote:
> On Tue, 25 Nov 2008 09:09:29 +0000
> Simon Huggins <[EMAIL PROTECTED]> wrote:
> > On Tue, Nov 25, 2008 at 02:06:04AM -0500, Daniel Dickinson wrote:
> > > On Mon, 6 Oct 2008 15:53:42 +0100
> > > Simon Huggins <[EMAIL PROTECTED]> wrote:
> > > > I've put an i386 debug package at:
> > > > http://the.earth.li/~huggie/xfce4-mpc-plugin-debug/
> > > This crashes immediately after adding it, entering the connection
> > > information, and clicking close
> > Hmm, maybe there was something wrong with the package though I suppose
> > it might mean that there is a buffer overflow directly in the code
> > that deals with storing those settings.
> > How long are your connection settings/username/password etc?
> hostname is 6 chars + 8 char + .2char domain and the user I'm running
> as is also 6 chars.

> The password on the other hand is 27 characters long.

> *** test ****

> Okay, a shorter password clears up the problem.  It is definitely
> password length that is problem.

Aha.  Right, can you try the package at:
http://the.earth.li/~huggie/xfce4-mpc-plugin_0.3.3-1huggie_i386.deb

I'll file a bug with upstream tonight but there's a fairly obvious
buffer overflow in mpd_send_password.

-- 
 _        [EMAIL PROTECTED]      -+*+-     fou, con et anglais      _
(_)   "No one - no government agency has jurisdiction over the   (_)
(_)                       truth." - Mulder                       (_)
  \___                                                        ___/

Attachment: signature.asc
Description: Digital signature

Reply via email to