retitle 495968 gpicview: CVE-2008-3791, CVE-2008-3904 insecure tempfile usage 
and code execution
thanks

Hi,
I discovered that this piece of code also allows code 
execution via crafted file names, have a look at:
http://marc.info/?l=oss-security&m=122014008313454&w=4
and
http://marc.info/?l=oss-security&m=122040004828615&w=4

this is CVE-2008-3904.

Cheers
Nico

-- 
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgp3dTqtJAS53.pgp
Description: PGP signature

Reply via email to