Comment 5 for bug 335643

Revision history for this message
Jamie Strandboge (jdstrand) wrote : Re: xdg-utils incorrectly parses output, allowing arbitrary text injection

Unmarking as security as it appears that at worst xdg-mime will simply echo back (part of) the filename and though while confusing and certainly a bug, it does not cross privilege boundaries or cause data loss. Presumably the user will recognize the echoed back text as the filename of the file that was queried. Filed as upstream bug https://bugs.freedesktop.org/show_bug.cgi?id=21018.