The question is: Do we want kdesudo to treat a command like this:

kdesudo "konqueror ;dolphin"

as two commands, or rather treat is as a parameter to the first command,
i.e. konqueror? Does the user *really* want to launch dolphin after
konqueror, or does he rather want to open the folder called ";dolphin"
with Konqueror?

So I wouldn't blame D3lphin yet. I can fix it so that it will prefix the
"Run as root" command properly, but the implications of this bug go
further than this.

-- 
kdesudo+dolphin leads to command execution vulnerability
https://bugs.launchpad.net/bugs/163417
You received this bug notification because you are a member of Ubuntu
Bugs, which is the bug contact for Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to