Public bug reported:

Binary package hint: swish-e

Architecture: amd64
Version: 2.4.3-4

The doc talks about using " '%p' " to guard against spaces in filenames.
That breaks the moment the filename contains a single quote, and may
well have other problems.

This looks like a security bug (as soon as swish-e is run with more
priviledges than the user who controls filenames has).

** Affects: swish-e (Ubuntu)
     Importance: Undecided
         Status: Unconfirmed

** This bug has been flagged as a security issue

-- 
Filename quoting problem
https://launchpad.net/bugs/78313

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to