Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 609404 - <kde-plasma/plasma-desktop-5.8.5-r2: Folder view does not honor kiorc settings
Summary: <kde-plasma/plasma-desktop-5.8.5-r2: Folder view does not honor kiorc settings
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugs.kde.org/show_bug.cgi?id=...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-02-15 10:38 UTC by Agostino Sarubbo
Modified: 2017-02-16 19:35 UTC (History)
0 users

See Also:
Package list:
=kde-plasma/plasma-desktop-5.8.5-r2
Runtime testing required: Yes
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2017-02-15 10:38:56 UTC
From ${URL} :

It was found that KDE plasma does not honor the setting for prompting when executing executable files on the desktop.

References:

https://www.reddit.com/r/linux/comments/5r6va0/how_to_easily_trick_file_manager_users_to_execute/dd51pxd/

Upstream bug:

https://bugs.kde.org/show_bug.cgi?id=375793


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Johannes Huber (RETIRED) gentoo-dev 2017-02-15 17:00:30 UTC
Upstream patch backported in =kde-plasma/plasma-desktop-5.8.5-r2.

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ef4dd781b1d8199027f0b0c55004446e5d3bd10d
Comment 2 Johannes Huber (RETIRED) gentoo-dev 2017-02-15 17:03:10 UTC
Dear arches please stabilize =kde-plasma/plasma-desktop-5.8.5-r2. Thanks in advance.

Test plan:
First arch should verify that backport is sufficient to fix the issue

Target:
amd64 x86
Comment 3 Agostino Sarubbo gentoo-dev 2017-02-16 10:26:21 UTC
amd64 stable
Comment 4 Agostino Sarubbo gentoo-dev 2017-02-16 17:27:23 UTC
x86 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 5 Johannes Huber (RETIRED) gentoo-dev 2017-02-16 19:10:33 UTC
Vulnerable version removed.

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=889f69c07452f24417b74d882b46ab5ab4670447
Comment 6 Thomas Deutschmann (RETIRED) gentoo-dev 2017-02-16 19:35:31 UTC
GLSA Vote: No

Repository is clean, all done.