Bug#860268: [Fwd: Re: Bug#860268: .desktop files can hide malware in Nautilus]

Jeremy Bicha jbicha at ubuntu.com
Wed Oct 11 18:46:31 UTC 2017


On Wed, Oct 11, 2017 at 2:34 PM, Phil Wyett <philwyett at kathenas.org> wrote:
> I have looked at both 'jessie' and 'wheezy'. Both are not affected by this
> specific issue and have mechanism(s) like stretch (with update) and newer
> versions of nautilus that display and require input when confronted with certain
> file types.

nautilus 3.22 introduced integrated (almost silent) tarball
decompression support which makes the test case for this vulnerability
a lot simpler.

Thanks,
Jeremy Bicha



More information about the pkg-gnome-maintainers mailing list