Firestarter Help runs Firefox as root
Bug #569 reported by
Stuart Bishop
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
firestarter (Ubuntu) |
Fix Released
|
High
|
MOTU Reviewers Team | ||
Bug Description
Choosing items from the Help menu fires off my preferred webbrowser to load the documentation
Choosing items from the Help menu fires off my preferred webbrowser to load the documentation. Unfortunatelly, as Firestarter is running as root so too is the spawned web browser.
Changed in firestarter: | |
assignee: | nobody → gnome |
Changed in firestarter: | |
assignee: | gnome → motu |
Changed in firestarter: | |
status: | Unconfirmed → Confirmed |
To post a comment you must log in.
to confirm and to add my thoughts:
In Dapper Beta2 LiveCD, Firefox will be launched with root privileges thru Firestarter Help, risking the installation by:
1. opening up the system to firefox bugs
2. user may continue browsing with firefox, not knowing that s/he's browsing with ROOT privileges, opening up the system to firefox vulnerabilities.
Can't we use yelp, or make firestarter launch help with sudo'ing user's privileges?