GLOBAL-6.6.1 released. [CVE-2017-17531]

Shigio YAMAGUCHI <[email protected]> Sat, 16 Dec 2017 14:38:43 +0900
Newsgroups gmane.comp.gnu.global.announce
Message-ID <CADJmJYp6WvMmUZMbhoAZYff_+TMCgtJVfGFAxk0d8mn=VW=nMw@mail.gmail.com>
--===============5795102126570529351==
Content-Type: multipart/alternative; boundary="001a114118c8c3620605606e87ca"

--001a114118c8c3620605606e87ca
Content-Type: text/plain; charset="UTF-8"

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256


GLOBAL-6.6.1 released. [CVE-2017-17531]

Hello hackers,

GLOBAL-6.6.1 is a bug fix release.

GLOBAL is a source code tagging system that works the same way across
diverse environments, for example, emacs, vi, less, bash, web browser
and etc. It is useful for hacking a large project.

[FIXED BUG]
o gozilla: A critical vulnerability (CVE-2017-17531) was found in a unknown
  function of gozilla(1). It allows remote attackers to execute arbitrary
  code via a crafted URL. Now it is fixed.

- - What is the unknown function?
Gozilla accepts a URL as an argument, and invokes a web browser with the
URL.
Though it is undocumented, it is implied in the online manual as follows:

> BUGS
>         Gozilla can accept not only source files but also text files,
>         directories, HTML files and even URLs, because it is omnivorous.

Impact:
    All gozilla(1) before GLOBAL-6.6.1 have the vulnerability.
    It allows remote attackers to execute arbitrary code via a crafted URL.
Workaround:
    Don't use the unknown function.
Solution:
    Install GLOBAL-6.6.1. The vulnerability was eliminated on this version.

You can download it from http://www.gnu.org/software/global/download.html

Shigio YAMAGUCHI <[email protected]>
-----BEGIN PGP SIGNATURE-----
Comment: For info see http://www.gnupg.org

iQEzBAEBCAAdFiEEfbo3OesTjKdebKVeKvmXe9peQbEFAlo0rX0ACgkQKvmXe9pe
QbGx7Af+Om3Vmc38+sGgMuGD+cYZe8ajK7aHigCbbx2jQ03xBaTVwrja4e5l21IS
1t3XtlGD4fG8oDJLR5RUYW4M1YpP6fhvzw2Sgek00aGPEMbbrMjmESEx8OQOOMMn
Uj8czeq1qogzbV/SOLmBRiV37JKRvRaFPmyY8bxIcxHx30h3fZtAU15R+ngijn1z
0cDOxLquglDXjtK2ksCxd/UHGU9w0BC8pv9LLM1q4c7XaAnYEGroT5Fd45MAb86y
rwT/nXp35lqSK16hduyCTNdvk948NNizccqXtgXTaEwoljsA3RLgKAXP0Uif9KtJ
Da4GcVXlHB0ssCsiRiLn4sRjXRfR1g==
=4WO1
-----END PGP SIGNATURE-----


-- 
Shigio YAMAGUCHI <[email protected]>
PGP fingerprint:
26F6 31B4 3D62 4A92 7E6F  1C33 969C 3BE3 89DD A6EB

--001a114118c8c3620605606e87ca
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>-----BEGIN PGP SIGNED MESSAGE-----</div><div>Hash: SH=
A256</div><div><br></div><div><br></div><div>GLOBAL-6.6.1 released. [CVE-20=
17-17531]</div><div><br></div><div>Hello hackers,</div><div><br></div><div>=
GLOBAL-6.6.1 is a bug fix release.</div><div><br></div><div>GLOBAL is a sou=
rce code tagging system that works the same way across</div><div>diverse en=
vironments, for example, emacs, vi, less, bash, web browser</div><div>and e=
tc. It is useful for hacking a large project.</div><div><br></div><div>[FIX=
ED BUG]</div><div>o gozilla: A critical vulnerability (CVE-2017-17531) was =
found in a unknown</div><div>=C2=A0 function of gozilla(1). It allows remot=
e attackers to execute arbitrary</div><div>=C2=A0 code via a crafted URL. N=
ow it is fixed.</div><div><br></div><div>- - What is the unknown function?<=
/div><div>Gozilla accepts a URL as an argument, and invokes a web browser w=
ith the URL.</div><div>Though it is undocumented, it is implied in the onli=
ne manual as follows:</div><div><br></div><div>&gt; BUGS</div><div>&gt;=C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Gozilla can accept not only source files but=
 also text files,</div><div>&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0directori=
es, HTML files and even URLs, because it is omnivorous.</div><div><br></div=
><div>Impact:</div><div>=C2=A0 =C2=A0 All gozilla(1) before GLOBAL-6.6.1 ha=
ve the vulnerability.</div><div>=C2=A0 =C2=A0 It allows remote attackers to=
 execute arbitrary code via a crafted URL.</div><div>Workaround:</div><div>=
=C2=A0 =C2=A0 Don&#39;t use the unknown function.</div><div>Solution:</div>=
<div>=C2=A0 =C2=A0 Install GLOBAL-6.6.1. The vulnerability was eliminated o=
n this version.</div><div><br></div><div>You can download it from <a href=
=3D"http://www.gnu.org/software/global/download.html">http://www.gnu.org/so=
ftware/global/download.html</a></div><div><br></div><div>Shigio YAMAGUCHI &=
lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt;</div><div>-----=
BEGIN PGP SIGNATURE-----</div><div>Comment: For info see <a href=3D"http://=
www.gnupg.org">http://www.gnupg.org</a></div><div><br></div><div>iQEzBAEBCA=
AdFiEEfbo3OesTjKdebKVeKvmXe9peQbEFAlo0rX0ACgkQKvmXe9pe</div><div>QbGx7Af+Om=
3Vmc38+sGgMuGD+cYZe8ajK7aHigCbbx2jQ03xBaTVwrja4e5l21IS</div><div>1t3XtlGD4f=
G8oDJLR5RUYW4M1YpP6fhvzw2Sgek00aGPEMbbrMjmESEx8OQOOMMn</div><div>Uj8czeq1qo=
gzbV/SOLmBRiV37JKRvRaFPmyY8bxIcxHx30h3fZtAU15R+ngijn1z</div><div>0cDOxLqugl=
DXjtK2ksCxd/UHGU9w0BC8pv9LLM1q4c7XaAnYEGroT5Fd45MAb86y</div><div>rwT/nXp35l=
qSK16hduyCTNdvk948NNizccqXtgXTaEwoljsA3RLgKAXP0Uif9KtJ</div><div>Da4GcVXlHB=
0ssCsiRiLn4sRjXRfR1g=3D=3D</div><div>=3D4WO1</div><div>-----END PGP SIGNATU=
RE-----</div><div><br></div><div><br></div>-- <br><div class=3D"gmail_signa=
ture"><div dir=3D"ltr"><div><div dir=3D"ltr"><div dir=3D"ltr"><div dir=3D"l=
tr"><div dir=3D"ltr"><div dir=3D"ltr">Shigio YAMAGUCHI &lt;<a href=3D"mailt=
o:[email protected]" target=3D"_blank">[email protected]</a>&gt;</div><div dir=3D=
"ltr"><div dir=3D"ltr">PGP fingerprint:=C2=A0</div><div dir=3D"ltr">26F6 31=
B4 3D62 4A92 7E6F =C2=A01C33 969C 3BE3 89DD A6EB</div></div></div></div></d=
iv></div></div></div></div>
</div>

--001a114118c8c3620605606e87ca--


--===============5795102126570529351==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Info-global mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/info-global

--===============5795102126570529351==--