sql queries not properly escaped

Bug #867651 reported by Alex Launi
264
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Music Lens
Confirmed
High
Alex Launi
Unity
Invalid
Undecided
Unassigned
unity-lens-music (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

queries containing a ' cause errors and cause banshee to not report results. Theoretically this could also allow for a sql injection vulnerability. This threat is minimal however, as anyone who can search in the dash can also open a terminal and run any arbitrary command on the db.

Alex Launi (alexlauni)
visibility: private → public
Changed in unity-lens-music:
status: New → Confirmed
importance: Undecided → High
assignee: nobody → Alex Launi (alexlauni)
milestone: none → 0.2.8
Changed in unity:
status: New → Confirmed
Changed in unity-lens-music (Ubuntu):
status: New → Confirmed
Revision history for this message
Stephen M. Webb (bregma) wrote :

Problem no longer applies in the current Unity stack because of the smart scopes.

Changed in unity:
status: Confirmed → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.