gnome thumbnailers should have an apparmor profile
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
gnome-desktop3 (Ubuntu) |
Triaged
|
Wishlist
|
Unassigned | ||
gnome-utils (Ubuntu) |
Triaged
|
Wishlist
|
Unassigned | ||
totem (Ubuntu) |
Triaged
|
Wishlist
|
Unassigned |
Bug Description
Binary package hint: gnome-control-
Nautilus normally uses gnome-thumbnail
$ gconftool-2 -g /desktop/
true
$ gconftool-2 -g /desktop/
gnome-thumbnail
If a flaw is discovered in a font library or Gnome and a user navigates to a directory that has a malicious font file, gnome-thumbnail
The same can be said for other thumbnailers. Nautilus also uses totem-video-
summary: |
- should have apparmor profile for gnome-thumbnail-font + gnome thumbnailers should have an apparmor profile |
Changed in totem (Ubuntu): | |
importance: | Undecided → Wishlist |
status: | New → Triaged |
description: | updated |
Changed in gnome-desktop (Ubuntu): | |
importance: | Undecided → Wishlist |
status: | New → Triaged |
description: | updated |
Changed in gnome-desktop (Ubuntu): | |
assignee: | nobody → Jamie Strandboge (jdstrand) |
affects: | gnome-control-center (Ubuntu) → gnome-utils (Ubuntu) |
affects: | gnome-desktop (Ubuntu) → gnome-desktop3 (Ubuntu) |
Changed in gnome-utils (Ubuntu): | |
status: | In Progress → Triaged |
Changed in totem (Ubuntu): | |
status: | In Progress → Triaged |
Changed in gnome-desktop3 (Ubuntu): | |
assignee: | Jamie Strandboge (jdstrand) → nobody |
Changed in gnome-utils (Ubuntu): | |
assignee: | Jamie Strandboge (jdstrand) → nobody |
Changed in totem (Ubuntu): | |
assignee: | Jamie Strandboge (jdstrand) → nobody |
tags: | added: raring saucy |
tags: | added: bionic disco |
tags: | removed: raring saucy |
tags: | added: focal jammy |
Attached is a preliminary profile to achieve this. It was tested with various font files based on http:// gfontview. sourceforge. net/features. html as well as with nautilus. It requires more testing before inclusion in Ubuntu. To try it out, copy it to /etc/apparmor. d/usr.bin. gnome-thumbnail -font and then perform: d/usr.bin. gnome-thumbnail -font
$ sudo apparmor_parser -r /etc/apparmor.
Feedback is welcome.