tags 654270 + upstream security
quit

Konstantinos Margaritis wrote:

> src/gtk2/gui_dialogs.c:59:37: error: format not a string literal and no 
> format arguments [-Werror=format-security]

Format string includes filename, which I believe can be arbitrary.
Looks like a low-severity security bug.  (Attacker tricks victim
into opening sound file with funny name.  Then...)

Hope that helps,
Jonathan



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to