Bug#516008: possible arbitrary code execution from .desktop files in email attachments

2009-02-22 Thread Markus Raab
Hello! Another issue regarding this bug is that noexec is not honored. While e.g. Shell Scripts will only be displayed instead of executed on noexec mounted Filesystems when you click on them - .desktop Files will be executed bypassing noexec security. Solution: Change .desktop file to

Bug#516008: possible arbitrary code execution from .desktop files in email attachments

2009-02-18 Thread Samuele Giovanni Tonon
Package: kdebase-bin Version: 4:3.5.9.dfsg.1-6 Severity: grave hello, as pointed out in http://www.geekzone.co.nz/foobar/6229 , at the moment KDE and gnome desktop allow to execute code by reading and interpreting a so called .desktop files which are launchers files without them being