On 9/20/06, walt <[EMAIL PROTECTED]> wrote:
On Wed, 20 Sep 2006 11:43:11 -1000, Kevin Brammer wrote:
...
> Nevermind.  I guess the moral of the story is rm -rf ~/.pan2 after
> each build.  Once I did that, no more crashes.

Well, maybe.  But...

Anyone who follows internet security problems will be aware that
'insufficient validation of user input' is responsible for a great
many software vulnerabilities.

Should a locally-stored config file be considered 'user input' in
this context?

In the short-run, clearly not:   Charles has enough trouble on his
hands just fixing major bugs without adding extra code to validate
the contents of pan's own config files.

But, in the long run it's a problem which definitely needs to be
solved.  This is an ideal research project for some eager computer
science grad student.  (Heh, maybe even a ten-year-old, nowadays!)


We may be talking about two different things.  I was referring to my
other email about the crashing when deleting headers while they were
updating.  I'm not sure which part of that generated your train of
thought.  :\

I just found that when I compiled .113, I had to delete my .pan2
directory, otherwise I suffered the same effects as .112.  Maybe it
was some pan-generated config file, or a corrupted cache of some
sort...no idea.


_______________________________________________
Pan-users mailing list
Pan-users@nongnu.org
http://lists.nongnu.org/mailman/listinfo/pan-users

Reply via email to