nautilus-3.22.3-4.el7

エラータID: AXSA:2018-2543:01

Release date: 
Friday, January 26, 2018 - 17:19
Subject: 
nautilus-3.22.3-4.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

Nautilus is the file manager and graphical shell for the GNOME desktop.

Security Fix(es):

* An untrusted .desktop file with executable permission set could choose its displayed name and icon, and execute commands without warning when opened by the user. An attacker could use this flaw to trick a user into opening a .desktop file disguised as a document, such as a PDF, and execute arbitrary commands. (CVE-2017-14604)

Note: This update will change the behavior of Nautilus. Nautilus will now prompt the user for confirmation when executing an untrusted .desktop file for the first time, and then add it to the trusted file list. Desktop files stored in the system directory, as specified by the XDG_DATA_DIRS environment variable, are always considered trusted and executed without prompt.

CVE-2017-14604
GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by
using the .desktop file extension, as demonstrated by an attack in
which a .desktop file's Name field ends in .pdf but this file's Exec
field launches a malicious "sh -c" command. In other words, Nautilus
provides no UI indication that a file actually has the potentially
unsafe .desktop extension; instead, the UI only shows the .pdf
extension. One (slightly) mitigating factor is that an attack requires
the .desktop file to have execute permission. The solution is to ask
the user to confirm that the file is supposed to be treated as a
.desktop file, and then remember the user's answer in the
metadata::trusted field.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. nautilus-3.22.3-4.el7.src.rpm
    MD5: 3df51aee44e2dbe82f7833b517f17e3c
    SHA-256: c20fea342e9e6597dd40c39dda0e19c490ad0a46186edb64ce16e97f524ec4e2
    Size: 5.01 MB

Asianux Server 7 for x86_64
  1. nautilus-3.22.3-4.el7.x86_64.rpm
    MD5: b66fd524f8282cef6303a197c158a0b2
    SHA-256: 36420c08cfa744d5f10bab8372bfea7fa07e212425c62bfd78cb433dedd8bf92
    Size: 2.84 MB
  2. nautilus-extensions-3.22.3-4.el7.x86_64.rpm
    MD5: 55cfcd5bd42005457c51ad33d55daf46
    SHA-256: 22ecfc7ad757dc5db5c9e3f4f9778e563b3a5fee40a199cd1295361923175d2c
    Size: 75.10 kB
  3. nautilus-3.22.3-4.el7.i686.rpm
    MD5: 72708032c09df809fd1c0c966fe765f2
    SHA-256: 62649b87b67d1ec9c5c2a4202c50df4dd9926b0f641ec440d31d0ef8008d5e17
    Size: 2.87 MB
  4. nautilus-extensions-3.22.3-4.el7.i686.rpm
    MD5: 56bd4b85d29812b8df3cc6613fb37e24
    SHA-256: 42ba1ae8e60895be1f130b0aa640c37f46f70640e5714e218bf43ef4cde04276
    Size: 74.97 kB