Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Fri, 15 Apr 2011 15:54:08 +0200
From: Yves-Alexis Perez <>
Subject: CVE request for Thunar (format string errors)

Two format string errors were recently fixed in Thunar (file manager for

The first one is (bug at  fixed in Thunar 1.2.1) and triggers when creating file from templates and calling it with a format string.

The second is and is triggered when copy/pasting a file named from a format string. There's no released version including the fix right now.

I've triggered the (second) bug using file named %s or %n but didn't
really manage to exploit it (it crashes just fine).

I'm not so sure it really needs a CVE so it's a request for discussion
as well :)

As a side note, I do use -Wformat -Wformat-security
-Werror=format-security (thanks to hardening-includes) for my Debian
builds, but as those function are wrappers of wrappers of wrappers to
printf() and stuff like that, -Wformat-security won't help. Is there a
way to work around that?


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.