"root" pictures may be previewed by other users

Bug #234561 reported by Alexander
This bug report is a duplicate of:  Bug #94230: thumbnails privacy violation hazard. Edit Remove
6
Affects Status Importance Assigned to Milestone
nautilus (Ubuntu)
Invalid
Low
Ubuntu Desktop Bugs

Bug Description

Binary package hint: nautilus

1) Copy some picture, for example, "1.jpg", to your home folder (also, for example).
2) Change "1.jpg" file access to (-rw-------), so only root can open this file for reading/writing and others cannot.
3) Open Home Folder in Nautilus. You cannot open this photo with the EYE of GNOME (for example)
4) Set "View as Icons" and you can preview this picture in nautilus.

ProblemType: Bug
Architecture: amd64
Date: Sat May 24 15:40:43 2008
DistroRelease: Ubuntu 8.04
ExecutablePath: /usr/bin/nautilus
NonfreeKernelModules: ath_hal
Package: nautilus 1:2.22.2-0ubuntu6
PackageArchitecture: amd64
ProcEnviron:
 PATH=/uusernamer/local/usernamebin:/uusernamer/local/bin:/uusernamer/usernamebin:/uusernamer/bin:/usernamebin:/bin:/uusernamer/gameusername
 LANG=en_US.UTF-8
 SHELL=/bin/bausernameh
SourcePackage: nautilus
Uname: Linux 2.6.22-14-generic x86_64

Tags: apport-bug
Revision history for this message
Alexander (ambzscyy) wrote :
Revision history for this message
A. Walton (awalton) wrote :

I think this a rather generic problem with image previews. We cache thumbnails early and often, and thumbnails are still considered valid for images that can't be read by the user if the file path checksum matches a thumbnail's name and the mtime of the file hasn't changed. A fix here would be to flush the thumbnail if we can't read the source file when we enter the folder, but that might incur performance penalties. As a work around you could touch the file after changing the permissions as that would trigger a re-thumbnail, which would generate a failed thumbnail as the file can't be read. Need to check libgnome and nautilus upstream to see if this is a known issue, or possibly a regression from Nautilus 2.20 (Launchpad is going down now, though).

Revision history for this message
Sebastien Bacher (seb128) wrote :

Thanks for the bug report. This particular bug has already been reported, but feel free to report any other bugs you find.

Changed in nautilus:
assignee: nobody → desktop-bugs
importance: Undecided → Low
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.