cut and paste of link alters permissions of linked file.

Bug #300777 reported by louis
262
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Nautilus
Confirmed
Unknown
nautilus (Ubuntu)
Triaged
High
Ubuntu Desktop Bugs

Bug Description

Binary package hint: nautilus

 $ ls -l
total 8
lrwxrwxrwx 1 louis louis 30 2008-11-21 19:17 Link to test-file -> /home/louis/tmp/test/test-file
-rw-r--r-- 1 louis louis 6107 2008-11-15 22:16 test-file
 $
 $ # after copy and paste in nautilus
 $ ls -l
total 8
lrwxrwxrwx 1 louis louis 30 2008-11-21 19:17 Link to test-file -> /home/louis/tmp/test/test-file
lrwxrwxrwx 1 louis louis 30 2008-11-21 19:19 Link to test-file (copy) -> /home/louis/tmp/test/test-file
-rwxrwxrwx 1 louis louis 6107 2008-11-21 19:17 test-file
 $
$ nautilus --version
GNOME nautilus 2.22.5.1
$ lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description: Ubuntu 8.04.1
Release: 8.04
Codename: hardy

I consider this a serious security problem.

Louis Jean-Richard

Revision history for this message
Kees Cook (kees) wrote :

Confirmed; the "Paste" of the symlink seems to trigger a mode change on the original. Eww.

Changed in nautilus:
status: New → Confirmed
Revision history for this message
Pedro Villavicencio (pedro) wrote :

I've sent this upstream at : http://bugzilla.gnome.org/show_bug.cgi?id=563511 ; thanks you.

Changed in nautilus:
assignee: nobody → desktop-bugs
importance: Undecided → High
status: Confirmed → Triaged
Changed in nautilus:
status: Unknown → Confirmed
Revision history for this message
Martin Erik Werner (arand) wrote :

This looks like a duplicate of Bug #418135, which has been fixed.
If not, feel free to re-open.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.