Vulnerability Bulletins

DSA-3994 nautilus - security update

   
Affected software Debian
 
Christian Boxdörfer discovered a vulnerability in the handling ofFreeDesktop.org .desktop files in Nautilus, a file manager for the GNOMEdesktop environment. An attacker can craft a .desktop file intended to runmalicious commands but displayed as a innocuous document file in Nautilus. Anuser would then trust it and open the file, and Nautilus would in turn executethe malicious content. Nautilus protection of only trusting .desktop files withexecutable permission can be bypassed by shipping

More info:

https://www.debian.org/security/2017/dsa-3994