Bug#684144: security issues with transmitted map cfgs

2012-09-23 Thread Martin Erik Werner
retitle 684144 manually downloaded map cfgs can directly execute text commands severity 684144 normal thanks. On speaking to the upstream developer, he pointed out that sauer does not actually transmit map cfg files, that's only something which happens in Red Eclipse (http://bugs.debian.org/cgi-bi

Bug#684144: security issues with transmitted map cfgs

2012-09-16 Thread Martin Erik Werner
On Sun, 2012-09-16 at 17:47 +0200, gregor herrmann wrote: > On Tue, 07 Aug 2012 13:53:47 +0200, Martin Erik Werner wrote: > > > The fix for Sauerbraten has been committed as > > http://sauerbraten.svn.sourceforge.net/viewvc/sauerbraten?view=revision&revision=4134 > > . > > Unfortunately it doesn

Bug#684144: security issues with transmitted map cfgs

2012-09-16 Thread gregor herrmann
On Tue, 07 Aug 2012 13:53:47 +0200, Martin Erik Werner wrote: > The fix for Sauerbraten has been committed as > http://sauerbraten.svn.sourceforge.net/viewvc/sauerbraten?view=revision&revision=4134 > . Unfortunately it doesn't work as is: In file included from engine/3dgui.cpp:8:0: engine/texte