Description of problem: The Firefox plugin uses os.system in an insecure fashion. Version-Release number of selected component (if applicable): mumbles-0.4-1.fc10 def open_uri(self, uri): mime_type = gnomevfs.get_mime_type(uri) application = gnomevfs.mime_get_default_application(mime_type) os.system(application[2] + ' "' + uri + '" &') This would be much better written to use the subprocess module and use an argument list like [application[2], uri], or else by using the shell's own substitution mechanism like this: os.environ['URI'] = uri os.system(application[2] + ' "$URI" &')
mumbles-0.4-9.fc10 has been submitted as an update for Fedora 10. http://admin.fedoraproject.org/updates/mumbles-0.4-9.fc10
Update has been sent to testing. Submitted upstream with patch, bug 2496077 Thanks, John
mumbles-0.4-9.fc10 has been pushed to the Fedora 10 testing repository. If problems still persist, please make note of it in this bug report. If you want to test the update, you can install it with su -c 'yum --enablerepo=updates-testing update mumbles'. You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F10/FEDORA-2009-0436
mumbles-0.4-9.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
mumbles-0.4-10.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/mumbles-0.4-10.fc11
mumbles-0.4-11.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/mumbles-0.4-11.fc11
mumbles-0.4-11.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.