RST/BitLocker - Do not make URLs translatable
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
ubiquity (Ubuntu) |
New
|
Medium
|
Unassigned |
Bug Description
In the debconf template and and the UI file, URL for bitlocker and rst are translatable introducing a risk for a translator to break the URL or more importantly to inject a malicious URL in the translation.
$ grep -r -E 'ubuntu.
debian/
debian/
gui/gtk/
gui/gtk/
ProblemType: Bug
DistroRelease: Ubuntu 20.04
Package: ubiquity (not installed)
ProcVersionSign
Uname: Linux 5.4.0-18-generic x86_64
NonfreeKernelMo
ApportVersion: 2.20.11-0ubuntu27
Architecture: amd64
CasperMD5CheckR
CurrentDesktop: ubuntu:GNOME
Date: Wed Apr 22 12:28:09 2020
InstallCmdLine: file=/cdrom/
InstallationDate: Installed on 2014-07-15 (2108 days ago)
InstallationMedia: Ubuntu 14.10 "Utopic Unicorn" - Alpha amd64 (20140520)
SourcePackage: ubiquity
UpgradeStatus: Upgraded to focal on 2018-03-24 (759 days ago)
summary: |
- RST/BitLocket - Do not make URL translatable + RST/BitLocker - Do not make URL translatable |
summary: |
- RST/BitLocker - Do not make URL translatable + RST/BitLocker - Do not make URLs translatable |
Changed in ubiquity (Ubuntu): | |
importance: | Undecided → Medium |
Subscribing foundations bugs team for visibility.