Summary: | Please consider sanitizing middle-click-pasted text control characters for security reasons | ||
---|---|---|---|
Product: | [Applications] konsole | Reporter: | Sami Liedes <sami.liedes> |
Component: | copy-paste | Assignee: | Konsole Developer <konsole-devel> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | jpalecek, martin.sandsmark |
Priority: | NOR | ||
Version: | 16.04.2 | ||
Target Milestone: | --- | ||
Platform: | Debian unstable | ||
OS: | Linux | ||
Latest Commit: | Version Fixed In: | ||
Sentry Crash Report: |
Description
Sami Liedes
2016-08-27 14:53:38 UTC
gnome-terminal fixed this only about a year ago. Tracking bug (with hopefully some additional useful information): https://bugzilla.gnome.org/show_bug.cgi?id=753197 Thanks Maybe showing the text being pasted with a warning would suffice. What do you think? You mean that instead of silently dropping control characters, Konsole would open a popup window showing the entire pasted text with control characters visible and ask if you want to paste it? I guess that would kind of solve the security problem, though I note that the text being pasted may be quite long for a popup (I don't know what the maximum size is, but I think at least hundreds of thousands of bytes is possible), and the malicious part could be hidden in the middle. Do you think someone relies on being able to paste control characters? I guess it's entirely possible. Already implemented a long time ago, this bug is probably a duplicate. (Noticed it because somehow a regression has sneaked in and Konsole has started warning about newlines as control characters, not newlines...). |