Package: xdg-utils
Version: 1.0.2-6.1
Severity: wishlist
Tags: patch

There has been some discussion[1][2][3] about security issues in 
.desktop files. There has bugreports both in Debian[4][5] and 
Mainstream[6].

A part of this solution would be to provide an unified script that would
handle the .desktop files. Which would mean that .desktop files would be
executables that had this script as shbang.

Considering I'm very much interested in seeing this issue solved, I had 
took the time to actually implement that script, so I'm now proposing 
that to be a debian-specific patch until freedesktop.org people accept 
that there is an issue (they think the current state-of-affairs is ok).

Honestly, I'm submitting this to the xdg-utils because I think it would 
be the natural place for such a script to be. But I'm seriously 
considering rolling over a new package if this doesn't get into this
package.

[1] http://www.geekzone.co.nz/foobar/6229
[2] http://www.geekzone.co.nz/foobar/6236
[3] http://lwn.net/Articles/178409/
[4] http://bugs.debian.org/515104
[5] http://bugs.debian.org/515106
[6] http://bugzilla.gnome.org/show_bug.cgi?id=572203

Attachment: xdg-launch
Description: Perl program

Reply via email to