Comment 15 for bug 823185

Revision history for this message
Chris Halse Rogers (raof) wrote :

I believe the colord 0.1.11-1ubuntu1 package now in the archive resolves the security concerns.

It runs as the colord user, which has access to /var/lib/colord, scanners, and sensor devices, and is otherwise unpriviledged. It also no longer automatically scans removable devices for colour profiles by default.

If that's ok, it'd be nice to get this MIR processed so the rest of g-c-c and g-c-m can build before beta :).