← Back to team overview

openjdk team mailing list archive

Re: [Bug 506702] Re: needs to block non-executable files from executing

 

On 19.01.2010 16:46, Kees Cook wrote:
>
> ** Attachment added: "sun-java6_6-16-1ubuntu1.debdiff"
>     http://launchpadlibrarian.net/38089345/sun-java6_6-16-1ubuntu1.debdiff

having the patch in this form is a major pain for uploads to older releases. 
please conditionalize this not to apply for anything else than lucid and newer.

-- 
needs to block non-executable files from executing
https://bugs.launchpad.net/bugs/506702
You received this bug notification because you are a member of OpenJDK,
which is subscribed to openjdk-6 in ubuntu.

Status in “mime-support” package in Ubuntu: Fix Released
Status in “nautilus” package in Ubuntu: In Progress
Status in “openjdk-6” package in Ubuntu: Fix Released
Status in “sun-java6” package in Ubuntu: In Progress
Status in “wine” package in Ubuntu: Fix Released
Status in “wine1.2” package in Ubuntu: New

Bug description:
Binary package hint: nautilus

Following the ratification of the "Execute-Permission Bit Required" security policy, several packages need to have their mime handlers updated to reject opening of various file types that are actually executables when they lack the execute bit.
https://wiki.ubuntu.com/SecurityTeam/Policies#Execute-Permission%20Bit%20Required





References