Comment 17 for bug 1520691

Revision history for this message
Bernd Dietzel (l-ubuntuone1104) wrote :

@edso
> ... so parameter issues sound merely academic from a security point of view. ...

Not so academic as you think , i could for example exploit the program Gufw with the legal parameter "disable" so the firewall went off, witch was not wanted and not shown in the gui.

> ... there is the "ominous" we agn. ;) ....

I used "we should ... " because it sounds so hard if i say "you have made some mistake" ... ;-)
I can help patching, but i found more than 30 Shell Injections in other python scripts , so ... you are not the only ones ;-)
My buglist where you can find some inspiration how the other ones fixed their bugs
https://bugs.launchpad.net/~l-ubuntuone1104/+bugs?orderby=-importance&start=0