Security Advisories (4)
CVE-2006-4484 (2008-10-01)

Buffer overflow in the LWZReadByte_ function in the GD extension in allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.

CVE-2007-4769 (2008-01-09)

The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (backend crash) via an out-of-bounds backref number.

CVE-2007-4772 (2008-01-09)

The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.

CVE-2007-6067 (2008-01-09)

Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted "complex" regular expression with doubly-nested states.

NAME

widget - Demonstration of Perl/Tk widgets

SYNOPSYS

widget [ directory ]

DESCRIPTION

This script demonstrates the various widgets provided by Tk, along with many of the features of the Tk toolkit. This file only contains code to generate the main window for the application, which invokes individual demonstrations. The code for the actual demonstrations is contained in separate ".pl" files in the "widget_lib" directory, which are autoloaded by this script as needed.

widget looks in the directory specified on the command line to load user contributed demonstrations. If no directory name is specified when widget is invoked and the environment variable WIDTRIB is defined then demonstrations are loaded from the WIDTRIB directory. If WIDTRIB is undefined then widget defaults to the released user contributed directory, "widtrib".

History

#
# Stephen O. Lidie, LUCC, 96/03/11.  lusol@Lehigh.EDU
# Stephen O. Lidie, LUCC, 97/01/01.  lusol@Lehigh.EDU
# Stephen O. Lidie, LUCC, 97/02/11.  lusol@Lehigh.EDU
# Stephen O. Lidie, LUCC, 97/06/07.  lusol@Lehigh.EDU
#     Update for Tk402.00x.  Total revamp:  WidgetDemo, Scrolled, released
#     composites, -menuitems, qw//, etcetera.  Perl 5.004 required.
# Stephen O. Lidie, LUCC, 98/03/10.  lusol@Lehigh.EDU
#     Update for Tk8.
# Stephen O. Lidie, LUCC, 98/06/26.  Stephen.O.Lidie@Lehigh.EDU
#     Add Common Dialogs for Tk800.007.
# Stephen.O.Lidie@Lehigh.EDU, 1999/11/29, Lehigh University.
#     Demo some "dash patch" changes.
# Stephen.O.Lidie@Lehigh.EDU, 2000/01/11, Lehigh University.
#     Update menubar to Tk 8, fix color palette Menubutton demo.

AUTHOR

Steve Lidie <Stephen.O.Lidie@Lehigh.EDU>