malformed gconftool-2 command spawns countless windows

Bug #717845 reported by bc81
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gconf-editor (Ubuntu)
Expired
Low
Unassigned

Bug Description

Binary package hint: gconf-editor

Ubuntu 10.10
gconf-editor: 2.32.0-0ubuntu1

i was in a terminal trying to figure out how to properly use gconftool-2 to hide the desktop's trash icon, when i accidentally stumbled on a potential security risk.

gconftool-2 --set /apps/nautilus/desktop/trash_icon_visible --type string "0"

running the above command will spawn "Starting File Manager..." windows indefinitely. the panel will be flooded with windows, the CPU will spike 100%, and rebooting/logging out has no effect; the windows will continue to spawn @ login time, even if in failsafe mode!

only after i was able to open gconf-editor, navigate to /apps/nautilus/desktop/trash_icon_visible, and unset the key manually (which i later found "gconftool-2 --unset /apps/nautilus/desktop/trash_icon_visible" had the same effect) did the windows start closing one by one, and the session returned to normal.

this is similar in behavior to malware on an unnamed operating system! think, if someone with malicious intent were to instruct a noob (such as myself) to run it, it could cause hardware damage from high CPU usage.

i hope this bug report has been thorough, and not overly dramatic :-) i will supply more info upon request.

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privilege boundaries nor directly cause loss of data/privacy. Please feel free to report any other bugs you may find.

security vulnerability: yes → no
visibility: private → public
Revision history for this message
Pedro Villavicencio (pedro) wrote :

Thank you for taking the time to report this bug and helping to make Ubuntu better. The issue that you reported is one that should be reproducible with the live environment of the Desktop CD of the development release - Oneiric Ocelot. It would help us greatly if you could test with it so we can work on getting it fixed in the next release of Ubuntu. You can find out more about the development release at http://www.ubuntu.com/testing/ . Thanks again and we appreciate your help.

Changed in gconf-editor (Ubuntu):
importance: Undecided → Low
status: New → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for gconf-editor (Ubuntu) because there has been no activity for 60 days.]

Changed in gconf-editor (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.