[sldev] Problem with script errors

Soft soft at lindenlab.com
Wed Sep 10 09:21:31 PDT 2008


On Wed, Sep 10, 2008 at 4:33 AM, Thomas Grimshaw <tom at streamsense.net> wrote:
> I am posting this here since this jira outlines a potential exploit with the
> way SL handles errors from scripts; I have only classified the Jira as a
> "new feature" since it's not a bug as such.. should I upgrade it?
>
> ====
>
> http://jira.secondlife.com/browse/SVC-3044

I've imported the two issues linked as children of SVC-3044 and
created a separate issue for the error sender being a NULL_KEY. I'm
not clear whether any change to the script error channel were
intentional, but the LSL team should have an answer in quick order,
which will determine how these are resolved.

When you believe an issue should be framed as an exploit, please
consider filing it in the SEC- category so we can roll out a fix
before widespread misuse. As potential exploits go, this one is pretty
minor but I still wanted to get that out there.

With objects in SEC-, only you and Lindens can see the issue while
it's being resolved. Once it's resolved, of course you'd be welcome to
have the JIRA moved into SVC- or VWR- or talk about it for full
disclosure. This is pretty similar to how most open source projects
work.


More information about the SLDev mailing list