[okular] [Bug 317856] [okular] saves opened file metadata in ~/.kde/share/apps/okular/docdata/ which can leak info, use hash instead

Dan Barrett bugzilla_noreply at kde.org
Sat Feb 8 23:29:48 GMT 2020


https://bugs.kde.org/show_bug.cgi?id=317856

Dan Barrett <kde at blazemonger.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |kde at blazemonger.com

--- Comment #3 from Dan Barrett <kde at blazemonger.com> ---
I just noticed this leaky behavior of okular and was about to file a security
bug, but I see someone else already did....

Please, at the very least, okular should "chmod 700
~/.local/share/okular/docdata." Right now, any user on the system can see file
paths in "docdata" by default.

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the Okular-devel mailing list