I love @kdecommunity and all, but this is quite the SNAFU. Oops. https://www.kde.org/info/security/advisory-20180208-2.txt …
-
Show this thread
-
Actually I think the advisory is wrong. As far as I can tell this has nothing to do with *mounting* devices. It's about the actions you get ("download photos with DigiKam" etc) - those basically run "/usr/bin/app <mountpoint>" and *that* is where they forgot to escape.
1 reply 1 retweet 6 likesShow this thread
This makes more sense because mounting should be handled via DBus/UDisks and there's no reason for the shell to get involved.
5:11 AM - 9 Feb 2018
0 replies
0 retweets
4 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.