[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [squeeze] permission to upload thunar-volman



On Sat, 2011-02-26 at 18:00 +0000, Adam D. Barratt wrote:
> Hi,
> 
> On Fri, 2011-02-18 at 22:13 +0100, Yves-Alexis Perez wrote:
> > would it be possible to make a stable upload, targeted at 6.0.1 or
> > 6.0.2, to disable default automount/autobrowse in thunar-volman?
> > 
> > It's only a matter of shipping a config file, so the following diff
> > should do the trick:
> 
> Apologies if I'm missing something obvious, but what's the motivation
> for making this change in stable?  The changelog for the proposed upload
> and the corresponding upload to unstable don't provide any further
> information afaics (hence the suspicion that I'm missing something).

There have been recent news about security issues with automount stuff
(linked with vulnerabilities in pdf parsers and thumbnailers). It
doesn't warrant a DSA, but I think it's safer to ship thunar-volman with
automount/autobrowse/autorun disabled by default.

Regards,
-- 
Yves-Alexis

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: