[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Security Issue of .desktop files



Le mardi 24 février 2009 à 17:36 -0300, Daniel Ruoso a écrit :
> I'm pretty happy with that solution (although I would prefer not having
> the "launch anyway"/"mark as trusted" box, but rather simply show the
> properties dialog for a non-executable-non-system-wide .desktop file
> (but I think that should go as an suggestion to upstream)).

How about discussing this with upstream instead of here? I already told
them that allowing to launch it anyway is a bad idea.

> I also would suggest that as a migration plan only, where we do turn
> all .desktop files into executables in the future, so we have a
> consistent environment.

What is the purpose of having system .desktop files executable?

> Also, as "mark as trusted" is making the file executable, are you
> planning to add a shbang to it?

No.

-- 
 .''`.      Debian 5.0 "Lenny" has been released!
: :' :
`. `'   Last night, Darth Vader came down from planet Vulcan and told
  `-    me that if you don't install Lenny, he'd melt your brain.

Attachment: signature.asc
Description: Ceci est une partie de message =?ISO-8859-1?Q?num=E9riquement?= =?ISO-8859-1?Q?_sign=E9e?=


Reply to: