workrave's idlelog is world readable

Bug #78959 reported by David
8
Affects Status Importance Assigned to Milestone
Workrave
Fix Released
Unknown
workrave (Ubuntu)
Fix Released
Medium
ubuntu-gnomemm

Bug Description

Binary package hint: workrave

Version: 1.8.3-1ubuntu1

~/.workrave/* is world readable

this folder contains idlelog..log which can be used to extract detailed information about when I am idle/not idle.

I consider this information to be private, and therefore I think ~/.workrave should be 700.

Revision history for this message
David (djs203) wrote :

see the attached graph for a demonstration of what data can be extracted from idelog..log

Revision history for this message
Daniel Holbach (dholbach) wrote :

Thanks for your bug report. Confirmed, somebody of the team should forward this bug upstream.

Changed in workrave:
assignee: nobody → desktop-bugs
importance: Undecided → Medium
status: Unconfirmed → Confirmed
Revision history for this message
Dean Sas (dsas) wrote :

The bug has been forwarded to the upstream developers, you can track it at http://issues.workrave.org/cgi-bin/bugzilla/show_bug.cgi?id=615

Changed in workrave:
status: Unconfirmed → Unknown
Changed in workrave:
status: Unknown → Confirmed
Changed in workrave:
assignee: desktop-bugs → ubuntu-gnomemm
Changed in workrave:
status: Confirmed → Fix Released
Revision history for this message
Murat Gunes (mgunes) wrote :

Persists in 1.8.4-2ubuntu1 (Gutsy) and upstream changelog [1] doesn't mention the change.

Revision history for this message
François Marier (fmarier) wrote :

This bug was fixed after the 1.8.4 release. I can confirm that it is resolved in 1.8.5.

Revision history for this message
Wouter Stomp (wouterstomp-deactivatedaccount) wrote :

Fixed: 1.8.5-4ubuntu2 is in ubuntu now.

Changed in workrave:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.