** Description changed:

  [Impact]
  
-  * Style::SquareButton writes a small png to /tmp/wut.png
-  * If a user creates /tmp/wut.png as a symlink to some file on the system 
writeable by the owner of the unity process, then he/she can destroy that file. 
+  * Style::SquareButton writes a small png to /tmp/wut.png
+  * If a user creates /tmp/wut.png as a symlink to some file on the system 
writeable by the owner of the unity process, then he/she can destroy that file.
  
  [Test Case]
  
-  * log out, login with the upgraded package and check for presence of
- "/tmp/wut.png"
+  * log out, login with the upgraded package and check for presence of 
"/tmp/wut.png"
+  * Test pkg - 
http://people.canonical.com/~ritesh/work/lp1051921-lens-bar-wut_png/ .
  
+ [Regression Potential]
  
- [Regression Potential] 
- 
-  * n/a
+  * n/a
  
  [Other Info]
-  
-  * Marc Deslauriers from the security team said it isn't a problem on Ubuntu 
because we have symlink restrictions (in this case part of the Yama LSM [1]).
  
-  * We believe, not everyone is necessarily running Yama LSM.
+  * Marc Deslauriers from the security team said it isn't a problem on
+ Ubuntu because we have symlink restrictions (in this case part of the
+ Yama LSM [1]).
+ 
+  * We believe, not everyone is necessarily running Yama LSM.

** Description changed:

  [Impact]
  
   * Style::SquareButton writes a small png to /tmp/wut.png
   * If a user creates /tmp/wut.png as a symlink to some file on the system 
writeable by the owner of the unity process, then he/she can destroy that file.
  
  [Test Case]
  
-  * log out, login with the upgraded package and check for presence of 
"/tmp/wut.png"
-  * Test pkg - 
http://people.canonical.com/~ritesh/work/lp1051921-lens-bar-wut_png/ .
+  * log out, login with the upgraded package and check for presence of
+ "/tmp/wut.png"
  
  [Regression Potential]
  
   * n/a
  
  [Other Info]
  
   * Marc Deslauriers from the security team said it isn't a problem on
  Ubuntu because we have symlink restrictions (in this case part of the
  Yama LSM [1]).
  
   * We believe, not everyone is necessarily running Yama LSM.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1051921

Title:
  lens-bar-keynavigation periodically writes to /tmp/wut.png

To manage notifications about this bug go to:
https://bugs.launchpad.net/unity/+bug/1051921/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to