[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [squeeze] permission to upload thunar-volman



On Sat, 2011-02-26 at 18:00 -0600, Ron Johnson wrote:
> Isn't it auto*run* which opens a vulnerability, and thus should be 
> disabled by default?

Autorun can leads to somehow direct exploitation.
> 
> Disabling automount & autobrowse seem to be security overkill. 

Autobrowse means a file manager is opened, which, by default, tries to
make thumbnails of files, which, in turn, can lead to code execution by
exploiting bugs in pdf parsers.

Regards,
-- 
Yves-Alexis

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: