Public bug reported:

Binary package hint: gnome-control-center

Nautilus normally uses gnome-thumbnail-font to provide font previews. Eg:
$ gconftool-2 -g /desktop/gnome/thumbnailers/application@x-font-ttf/enable
true
$ gconftool-2 -g /desktop/gnome/thumbnailers/application@x-font-ttf/command
gnome-thumbnail-font %u %o

If a flaw is discovered in a font library or Gnome and a user navigates
to a directory that has a malicious font file, gnome-tumbnail-font could
be used to execute arbitrary code, write out to files or leak
information. Providing an apparmor profile for gnome-thumbnail-font
would be a good step towards proactively protecting the user from this
sort of attack.

** Affects: gnome-control-center (Ubuntu)
     Importance: Wishlist
     Assignee: Jamie Strandboge (jdstrand)
         Status: In Progress


** Tags: apparmor

** Changed in: gnome-control-center (Ubuntu)
   Importance: Undecided => Wishlist

** Changed in: gnome-control-center (Ubuntu)
       Status: New => In Progress

** Changed in: gnome-control-center (Ubuntu)
     Assignee: (unassigned) => Jamie Strandboge (jdstrand)

** Tags added: apparmor

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to gnome-control-center in ubuntu.
https://bugs.launchpad.net/bugs/715874

Title:
  should have apparmor profile for gnome-thumbnail-font

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

Reply via email to