Debian Bug report logs - #672215
[supybot] math.calc can be used to crash the computer where the bot is running

version graph

Package: supybot; Maintainer for supybot is James McCoy <jamessan@debian.org>; Source for supybot is src:supybot (PTS, buildd, popcon).

Reported by: mkaysi@users.sourceforge.net

Date: Wed, 9 May 2012 07:48:05 UTC

Severity: important

Tags: fixed-upstream

Found in version supybot/0.83.4.1.ds-2

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, James Vega <jamessan@debian.org>:
Bug#672215; Package supybot. (Wed, 09 May 2012 07:48:08 GMT) (full text, mbox, link).


Acknowledgement sent to mkaysi@users.sourceforge.net:
New Bug report received and forwarded. Copy sent to James Vega <jamessan@debian.org>. (Wed, 09 May 2012 07:48:08 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Mika Suomalainen <mkaysi@users.sourceforge.net>
To: submit@bugs.debian.org
Subject: [supybot] math.calc can be used to crash the computer where the bot is running
Date: Wed, 09 May 2012 10:37:57 +0300
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Package: supybot
Version: 0.83.4.1.ds-2
Severity: important

- --- Please enter the report below this line. ---

Subject tells everything.
Example command:
> !math calc factorial(999999)

This issue has been fixed at least in fork Limnoria,
https://github.com/ProgVal/Limnoria/ .

Supybot upstream can be considered as dead.

- --- System information. ---
Architecture: amd64
Kernel:       Linux 3.2.0-2-amd64

Debian Release: wheezy/sid
  500 unstable        www.debian-multimedia.org
  500 unstable        ftp.fi.debian.org
  500 unstable        ftp.debian.org
  500 unstable        ftp.acc.umu.se
  500 unstable        deb.torproject.org
  500 testing         dl.google.com
  500 stable          download.webmin.com
  500 stable          dl.google.com
  500 sid             www.lamaresh.net
  500 oneiric         ppa.launchpad.net
  500 experimental-sid deb.torproject.org
  500 all             liveusb.info

- --- Package information. ---
Depends              (Version) | Installed
==============================-+-============
python                (>= 2.3) | 2.7.2-10
python-support     (>= 0.90.0) | 1.0.14


Recommends             (Version) | Installed
================================-+-===========
python-simplejson                | 2.5.0-1
 OR python              (>= 2.6) | 2.7.2-10
python-feedparser                | 5.0.1-1


Suggests                  (Version) | Installed
===================================-+-===========
python-twisted-core                 | 12.0.0-1
python-twisted-names                | 11.1.0-1
python-sqlite                       |
python-dictclient                   |
python-dateutil                     | 1.5-1





- -- 
Mika Suomalainen
gpg --keyserver pool.sks-keyservers.net --recv-keys 4DB53CFE82A46728
Key fingerprint = 24BC 1573 B8EE D666 D10A  AA65 4DB5 3CFE 82A4 6728
http://mkaysi.github.com/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.19 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBAgAGBQJPqh7TAAoJEE21PP6CpGcou2MP/2Poo0iTUNbxyUMAnv4LE+eP
QOlk/rIyvWf4p1BlmszVXf0JlacBQTd5XU6mRB0yQYRIfmwyx1hDILhNb+HlkPJ4
dl5zKDYeoEdcVtL2T7bVIOLVigAnNGh3JcmeGIFXVuhmzYiAiVNCf1FoIHbzkgad
6+c+e8gOz2Dc+GyWQYHrRt16b9mpPs7NmDO83z6gTod8LGsuLWbuCkiOujWnZu0x
zv7clFaWYqcAq0fLtm4MO8g7bNNpb28lol6Vm1qyKul6cgbCB2tLeel/uXdBDqqo
bjK17QjIrdTwDUclRC1Tb/WNTgoXhHU1212XZMUB91JcMzvTBVAlRI3t9etHMLOi
ycEMRGA2KeqioQRPDVnLwvni5vPUaegXIMVAuUq3gXSW6Sgi5TgG8PPjP3nWOybH
ahYHzPFzjO6QXO7XMyrzlyXLopuKIc7sAk4d/4ORSahAu9sdHHJ07cTqcYPe8r7N
3N7s7ckqIqkyIZPyN4wFz9uas2+9E5sH57jb3lM7dOff+TWdQnCCT8BSfTIjJNo3
JfIPA81GO0w6/c4VSB5XWwX7Xk3dyv5lyDBxEVPM3RNPP+J5t3aZnOKGGAif5g4r
y0LA3etZPjYwvoHshCahJRkpfHKdj63C3cWmYaxc426zCMoJComclP4dgF+IVz2a
xz6C44c3P0UV0T2puKyP
=Ntsw
-----END PGP SIGNATURE-----




Added tag(s) fixed-upstream. Request was from James McCoy <jamessan@debian.org> to control@bugs.debian.org. (Thu, 24 May 2012 00:51:03 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sat Jan 13 14:32:18 2018; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.