|
Message-ID: <20090107083206.GA16641@pcpool00.mathematik.uni-freiburg.de> Date: Wed, 7 Jan 2009 09:32:06 +0100 From: "Bernhard R. Link" <brlink@...ian.org> To: oss-security@...ts.openwall.com Subject: Re: Fwd: Using xdg-open in /etc/mailcap causes hole in Firefox (Demonstration/Exploit included) * Josh Bressers <bressers@...hat.com> [090106 20:47]: > Here's a heads up for everyone (I've CCd the discoverer) > ----- Forwarded Message ----- [...] > This page delivers a .desktop file with the mime-type "application/pdf". In default configuration, Firefox offers to open this file with the default application, which is xdg-open. Just one click on "OK" (and most users won't have a closer look at the dialog!) and the content in the .desktop file is immediately executed! I guess that is what people get for reinventing "see", they get the exact same security problems other browser/"generic viewer" combinations had years ago.... And xdg-open had not even a way to specify the mime-type... </rant> Bernhard R. Link
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.