*** This bug is a security vulnerability ***
Public security bug reported:
I'm using version 1.06-0ubuntu1 and went to download a torrent to find
out that it defaults to a users home directory. What if someone put a
.profile or a .bashrc or any . file in their torrent. We don't want to
allow someone to overwrite their config files potentially running
malicious things. Xchat used to do this with DCC sends, but now it
uses ~/.downloads or something other than ~/ anyway.
Since Gutsy introduced dedicated directories in our home folders, lets
use them! Isn't there a "~/Downloads" folder that we could default to
for our torrenting?
** Affects: transmission (Ubuntu)
Importance: Undecided
Status: New
** Visibility changed to: Public
--
Transmission should not default to ~/ to save files
https://bugs.launchpad.net/bugs/198265
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs