27 March 2012

evilvte 0.5.1 released

Changelog:
0.5.1
 * Better compatibility with some compilers and
   CFLAGS, Thanks to Daniel Richard G.
   <skunk AT iSKUNK DOT ORG>
 * Support key bindings for ALT_SHIFT,
   CTRL_ALT_SHIFT, and CTRL_SHIFT
 * Auto-detect gtk_*_resize_grip in dlopen() mode
 * Fix a potential bug for HOTKEY_SCROLL_ONE_PAGE_*
 * Strict minimum font size to 1
 * Hide DEFAULT_ENCODING, PROGRAM_NAME, and
   PROGRAM_VERSION
 * Make everything GTK+ 3.4.0 compatible

 * How to report bug, request feature,
   or submit patch for evilvte

09 March 2012

[bug] libVTE scrollback buffer written to disk

http://www.climagic.com/bugreports/libvte-scrollback-written-to-disk.html

Summary:
-----------------------------------------------------------------------
  Due to the way the history buffer is saved in terminal emulators
  using libVTE after version 0.21.6, data from inside your terminal
  window can end up on your local filesystem. This is most likely
  unexpected behavior in a terminal emulator and represents a very
  significant security issue.

Worse case scenario:
-----------------------------------------------------------------------
  Classified, secret or medical information that was accessed through a
  terminal window was thought to be safe because it was on a remote server
  and only accessed via SSH, but now its also on the hard drive that is
  for sale online or stolen without having been wiped because this
  issue was not accounted for.