Bug#1043334: urlview is insecure: URL visible to everyone with commands like ps

2023-12-03 Thread наб
Control: tags -1 + fixed-upstream On Wed, Aug 09, 2023 at 11:18:31AM +0200, Vincent Lefevre wrote: > Package: urlview > > So it should provide a way to pass the URL via a pipe. For instance, > this can be useful with xclip (the user can then paste the URL to the > web browser). Agree, this would

Bug#1043334: urlview is insecure: URL visible to everyone with commands like ps

2023-08-09 Thread Vincent Lefevre
Package: urlview Version: 0.9-23.1 Severity: important Tags: security upstream X-Debbugs-Cc: Debian Security Team Because urlview passes the URL as an argument, the URL can be visible to everyone with commands like ps, while the URL may contain private information, e.g. used for anthentication. T