upgrade to gutsy requires user to make poor security choice

Bug #161888 reported by Chris Thomas (CTho)
268
Affects Status Importance Assigned to Milestone
update-manager (Ubuntu)
Fix Released
Wishlist
Michael Vogt
Gutsy
Won't Fix
Undecided
Unassigned

Bug Description

1. System->Administration->Upgrade Manager
2. Click "Upgrade" next to "New distribution release '7.10' is available"
3. Click "Upgrade"
4. Observe "Enter your password to perform administrative tasks" prompt. It says, "The application '/tmp/tmpXf8_U1/gutsy' lets you modify essential parts of your system". In general, it's probably bad practice to get users in the habit of giving root privileges to random files in /tmp.

Changed in update-manager:
assignee: nobody → mvo
importance: Undecided → Wishlist
milestone: none → ubuntu-8.04
status: New → Confirmed
Revision history for this message
Jonathan Prior (behe) wrote :

This would probably mean instead of installing the System Upgrade helper in the /tmp folder, it would be installed in /bin or /usr/bin or somewhere where it could be considered as a "proper" program, even if it is going to be removed after use.

Revision history for this message
Michael Vogt (mvo) wrote :

Thanks for your bugreport.

This is fixed in my bzr tree and will be part of the next upload into hardy. If we want this for gutsy, we will have to issue a SRU.

Changed in update-manager:
status: Confirmed → Fix Committed
Revision history for this message
Jonathan Prior (behe) wrote :

So where is the upgrade manager installed to in your tree? Is it /usr/bin like I suggested?

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package update-manager - 1:0.87.18

---------------
update-manager (1:0.87.18) hardy; urgency=low

  * DistUpgrade/DistUpgradeCache.py:
    - remove mail-notificaton, gnome-translate from hardy
      quirks list (LP: #215690)
  * UpdateManager/DistUpgradeFetcher.py:
    - use sensible gksu prompt when asking for release
      upgrade (LP: #161888)

 -- Michael Vogt <email address hidden> Mon, 14 Apr 2008 21:44:43 +0200

Changed in update-manager:
status: Fix Committed → Fix Released
Revision history for this message
Sergio Zanchetta (primes2h) wrote :

The 18 month support period for Gutsy Gibbon 7.10 has reached its end of life -
http://www.ubuntu.com/news/ubuntu-7.10-eol . As a result, we are closing the
Gutsy task.

Changed in update-manager (Ubuntu Gutsy):
status: New → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.