Comment 13 for bug 1648806

Revision history for this message
Donncha O Cearbhaill (donnchac) wrote :

There is a another risk where the `RespawnCommand` or `ProcCmdline` fields in a crash file are executed when a user clicks "Restart" from the apport-gtk prompt. This is not a vulnerability as it is the intended behaviour

However it may be safer to hide the restart option when opening a non-local crash file (when a .crash is opened directly from the Desktop). Instead the "Restart" button would only be shown when a generated crash file is opened by the `update-notifier` inotify watcher.