[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: .desktop arbitrary program execution (was: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution)



On Wednesday 19 January 2005 04:45, David Mandelberg wrote:
> Attached.
>
> Save to your GNOME/KDE desktop (like many newbies do) and double click  the
> new icon. .desktop files (currently) don't need the x bit set to work, so
> no chmod'ing is necessary.

Hmm, attached a screenshot how every MUA should handle this.

With this display, no attachment ever could fake its way into naive[1] users 
brains.



Regards, David


[1] naive != stupid

Attachment: kmail.png
Description: PNG image


Reply to: