Public bug reported:

Binary package hint: logjam

Logjam does not appear to handle user input in the proxy text field
properly. I feel it might lead to a security problem, but then again,
maybe not.

A user can specify a proxy in logjam, but the user interface does not
make it clear how to specify the port. The user might think she has to
put hostname:port, but that leads to an error (see my other bug,
https://bugs.launchpad.net/ubuntu/+source/logjam/+bug/125769 )

She might think she has to put http:// in front of the address, but that
leads to an error that has mostly understandable content: logjam
apparently connects to port 80. The error shown in the dialog was the
http header response.

I figure connecting to port 80 a bit unexpectedly might lead to security
problems. At least the user interface should be updated so it's clear
how the user should specify the port, and also specifying URI's
shouldn't change the behavior.

** Affects: logjam (Ubuntu)
     Importance: Undecided
         Status: New

-- 
logjam proxy settings difficult to understand
https://bugs.launchpad.net/bugs/125799
You received this bug notification because you are a member of Ubuntu
Bugs, which is the bug contact for Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to