[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Security Issue of .desktop files



Le mardi 24 février 2009 à 22:53 +0100, Yves-Alexis Perez a écrit :
> Not exactly. The “safe” .desktop file was in the link I pasted on
> another mail in the thread:
> 
>  /* check if the file tries to look like a regular document (i.e.
>   * a display name of 'file.png'), maybe a virus or other malware.
>   */

> Basically, when the .desktop tries to trick the user, it won't be
> executed.

So this amounts to approximately the same level as the patched nautilus
currently in Debian. However this is insufficient, since it is easy to
trick the user into launching a “safe” .desktop file which is actually
malware.

-- 
 .''`.      Debian 5.0 "Lenny" has been released!
: :' :
`. `'   Last night, Darth Vader came down from planet Vulcan and told
  `-    me that if you don't install Lenny, he'd melt your brain.

Attachment: signature.asc
Description: Ceci est une partie de message =?ISO-8859-1?Q?num=E9riquement?= =?ISO-8859-1?Q?_sign=E9e?=


Reply to: