[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution



Adam Lydick wrote:
> Fantastic idea! (as others have said) Have you filed a bug against
> nautilus (and other shells) to this effect? You might also file one at
> the various upstream bug tracking systems as well.
I'm glad you like it (I do too), but it wasn't my idea. Search the ubuntu-devel
list archives at lists.ubuntu.com for the "Scary .desktop behaviour" thread.

>
> I was pondering complicated solutions with alternate stream hacks (like
> XPSP2 uses), but your suggestion is much simpler and would require
> minimal changes to the system.
>
> On Wed, 2005-01-19 at 06:52 -0500, David Mandelberg wrote:
> [snip]
>
>
>>I'm just suggesting that it should be harder for them to shoot themselves in the
>>foot i.e. by making .desktop's have the x bit before they can be launched.
>
>
> [snip]
>


--
-----BEGIN GEEK CODE BLOCK-----
Version: 3.1
GAT/CM$/CS>$/CC/IT$/M/S/O/U dpu s+:++ !a C++$>C+++$
UB+++>++++$L++++$*-- P+>++$ L+++(++++)$ E-(---) W+++>$ N(+) o? K-
w--(---) O? M V? PS++@ PE-@ Y+@ PGP++(+++)>$ t? 5? X? R tv--(-)
b++(+++)@ DI? D? G e->++++ h* r? z*
------END GEEK CODE BLOCK------

David Mandelberg
mandelbergd@eth0.is-a-geek.org

Attachment: signature.asc
Description: OpenPGP digital signature


Reply to: