Firefox proposes to open .exe files with Wine

Bug #24829 reported by Colin Leroy-Mira
14
Affects Status Importance Assigned to Milestone
firefox (Ubuntu)
Invalid
Undecided
Unassigned
wine (Ubuntu)
Fix Released
High
Paul Sladen

Bug Description

Hi,

If wine is installed, Firefox proposes, by default, to open them with wine. I
think it's a security risk. People will get Windows viruses via Wine.

Revision history for this message
Colin Leroy-Mira (colin-colino) wrote :

Created an attachment (id=4832)
Screenshot of the download dialog

Revision history for this message
Ian Jackson (ijackson) wrote :

This problem is serious, if it can be reproduced.

Revision history for this message
Dennis Kaarsemaker (dennis) wrote :

It can.

Revision history for this message
Colin Watson (cjwatson) wrote :

Edited IRC log from today:

16:54 < Diziet> There has to be a whitelist.
16:55 < Keybuk> the mime type handling list is the whitelist
16:55 < Keybuk> we just shouldn't put dangerous things in that
16:55 < Diziet> But it's full of stuff like `run wine on this .exe'.
16:55 < Keybuk> now that's a valid bug ;)
16:55 < Diziet> But if you have the .exe installed on your machine and
double-click on it it _ought_ to run it with Wine !
16:55 < slomo> wine on every *.exe is wrong anyway
16:56 < Kamion> .exe files should just be made executable and use binfmt-support
16:56 < Kamion> then if you drop the MIME handling for them, non-executable .exe
files are safe
16:56 < Kamion> and executable ones work as expected
16:57 < Diziet> kamion: That would be a reasonable approach.
16:57 < Keybuk> Kamion: that's how you have to do it for the mono ones already
16:57 < Kamion> Keybuk: indeed so
16:57 < Diziet> So 18701 is a bug in the wine package ?
16:57 < Kamion> Diziet: in whatever does the MIME handling, I'd've thought
16:57 < Diziet> Err, wine presumabely specifies its own mailcap entries or what
have you.,
16:58 < Kamion> I don't know the layout
16:58 < Kamion> but if so, I'd think so, yes

Changed in firefox:
status: Unconfirmed → Confirmed
Revision history for this message
Matt Zimmerman (mdz) wrote :

Ian, what are we doing about this for 6.06? I'm fine with removing the entry from the MIME database if that's the simplest and safest approach.

Revision history for this message
Ian Jackson (ijackson) wrote : Re: [Bug 24829] Re: Firefox proposes to open .exe files with Wine

Matt Zimmerman writes ("[Bug 24829] Re: Firefox proposes to open .exe files with Wine"):
> Ian, what are we doing about this for 6.06? I'm fine with removing the
> entry from the MIME database if that's the simplest and safest approach.

I've put this on my list and will remove the entry from the MIME
database unless someone else gets there first :-).

Ian.

Revision history for this message
Joseph Garvin (k04jg02) wrote :

I don't really think this is much of a security risk. Most windows viruses won't work with wine anyway, and a windows virus isn't nearly as dangerous run on a linux system because of the file permissions system. The absolute worst this could do is trash your home folder, and only then if it was a virus that acted on what's in the folder its run in -- most viruses try to set themselves up as services (which wine won't do) or overwrite windows system files (which won't exist).

Revision history for this message
Colin Leroy-Mira (colin-colino) wrote :

On 12 May 2006 at 17h05, Joseph Garvin wrote:

Hi,

> The absolute worst this could do is trash your home folder,

What do you think is important on a desktop system? Your distro which
you reinstall in about 20 minutes, or your home folder with gigabytes
of data in it?

> and only then if it was a virus that acted on what's in the folder
> its run in -- most viruses try to set themselves up as services
> (which wine won't do) or overwrite windows system files (which won't
> exist).

This is still completely idiotic behaviour.

--
Colin

Revision history for this message
Paul Sladen (sladen) wrote :

 wine (0.9.9-0ubuntu2) dapper; urgency=low
 .
   * Remove insecure mailcap entries; MS Windows '.exe' files should be run
     using 'binfmt-misc' support instead. (Closes: Ubuntu #24829)
   * Fix build-deps on 'libicu-dev'

Changed in firefox:
assignee: ijackson → sladen
status: Confirmed → Fix Released
Revision history for this message
Eduardo Silva (jobezone) wrote :

oops, I acidently clicked a button, and added firefox (ubuntu) to packages affected by this bug. I've rejected it again.

Changed in firefox:
status: Unconfirmed → Rejected
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.