[X2Go-Dev] Bug#722: Bug#722: Fwd: [Bug 1179869] New: [abrt] x2goclient: ref(): x2goclient killed by SIGSEGV

Mike Gabriel mike.gabriel at das-netzwerkteam.de
Thu Jan 8 10:48:32 CET 2015


Control: severity -1 important
Control: retitle -1 add sanity checks when processing stdout of X2Go  
Server commands

Hi Orion,

On  Mi 07 Jan 2015 18:56:36 CET, Orion Poplawski wrote:

> Package: x2goclient
> Version: 4.0.2.1
>
> This crashing here:
> x2goSession ONMainWindow::getSessionFromString ( const QString& string )
> {
>     QStringList lst=string.split ( '|' );
>     x2goSession s;
>     s.agentPid=lst[0];
>     s.sessionId=lst[1];
>
> looks like the session string is corrupted and doesn't have the expected
> number of elements.  Need some error checking here.
>

Unfortunately, X2Go Client code does no sanitizing at all at most  
place. It simply expects that the X2Go Server on the other end is  
working correctly (which it sometimes is not)...

Raising severity to important...

Mike

-- 

DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148

GnuPG Key ID 0x25771B31
mail: mike.gabriel at das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 819 bytes
Desc: Digitale PGP-Signatur
URL: <http://lists.x2go.org/pipermail/x2go-dev/attachments/20150108/48b3e679/attachment.pgp>


More information about the x2go-dev mailing list