Red Hat Bugzilla – Bug 121274
Remote computer can upload arbitrary files to user's home directory.
Last modified: 2007-11-30 17:10:40 EST
When gnome-obex-server is running, a remote device can upload
arbitrary files (such as a .rhosts file) to the home directory.
Rather than silently dumping files into the home directory (or indeed
any directory), gnome-obex-server should bring up a dialogue box
stating what has been received, and asking what to do with it (save
as, open with...) just as we'd do with an email attachment.
At least it should dump to its own directory rather than $HOME.