Fwd: Re: Security issue in 4.2

Tom Albers tomalbers at kde.nl
Sun Jan 25 19:00:55 CET 2009


forward per request of Chani.

Toma

Op Sunday 25 January 2009 18:57 schreef Chani <chanika at gmail.com>:
> [sending again - the mail doesn't seem to have reached the list, nor have I 
> gotten an "awaiting moderation" message]
> 
> please cc me, I'm not subscribed.
> 
> the problem is a bugfix gone awry that exposes a way to get a filedialog on the 
> screensaver whenever widgets are turned on.
> 
> the good news is, widgets are disabled by default, so this only affects people 
> who enable them.
> 
> however, this bug changes widgets from "secure if you think before adding 
> plasmoids" to "not secure, period" - and there's no warning when you enable 
> them.
> 
> the attached patch, committed in revision 916332, fixes it.
> 
> -- 
> This message brought to you by eevil bananas and the number 3.
> www.chani3.com

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: text/x-diff
Size: 735 bytes
Desc: not available
Url : http://mail.kde.org/pipermail/release-team/attachments/20090125/bf2ecc03/attachment.bin 
-------------- next part --------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEABECAAYFAkl8qCcACgkQeGbAwpIS3GxR2ACfZQMCSxWkbwXpLALiglBHG0v7
2nEAnjObT/zsb4JFF9M4YZQvPa7rjCx9
=o9UE
-----END PGP SIGNATURE-----


More information about the release-team mailing list