CVE-2017-14604

Priority
Description
GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by
using the .desktop file extension, as demonstrated by an attack in which a
.desktop file's Name field ends in .pdf but this file's Exec field launches
a malicious "sh -c" command. In other words, Nautilus provides no UI
indication that a file actually has the potentially unsafe .desktop
extension; instead, the UI only shows the .pdf extension. One (slightly)
mitigating factor is that an attack requires the .desktop file to have
execute permission. The solution is to ask the user to confirm that the
file is supposed to be treated as a .desktop file, and then remember the
user's answer in the metadata::trusted field.
Notes
 mdeslaur> fixing this in stable releases would result in the user getting
 mdeslaur> an unexpected "Untrusted application launcher" dialog on existing
 mdeslaur> .desktop files. Dialog changes would also need new translations.
Package
Upstream:released (3.23.90)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Trusty/esm:DNE (trusty was needed)
Ubuntu 16.04 LTS (Xenial Xerus):needed
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (1:3.26.0-0ubuntu1)
Ubuntu 18.10 (Cosmic Cuttlefish):not-affected (1:3.26.0-0ubuntu1)
Ubuntu 19.04 (Disco Dingo):not-affected (1:3.26.0-0ubuntu1)
Ubuntu 19.10 (Eoan):not-affected (1:3.26.0-0ubuntu1)
Patches:
Upstream:https://github.com/GNOME/nautilus/commit/1630f53481f445ada0a455e9979236d31a8d3bb0
More Information

Updated: 2019-04-26 14:20:02 UTC (commit 30899e40836d26e1bb5f0b072d31fd87b6cf3bd4)