[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kmail-devel
Subject:    Re: Fwd: possible security problem in kmail 1.6
From:       Waldo Bastian <bastian () kde ! org>
Date:       2004-02-15 20:15:45
Message-ID: 200402152115.45086.bastian () kde ! org
[Download RAW message or body]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

That's really up to the application developer to decide. re-use can be 
prevented by using either DCOPClient::detach() or 
DCOPClient::setAcceptCalls(false);

Cheers,
Waldo

On Sun February 15 2004 20:41, Andreas Pour wrote:
> Hi,
>
> IIUTC, this seems to be an architectural design flaw in KUniqueApplication.
>  If all the user-visible windows have been closed, a flag should be set and
> the running instance not re-used, due to the obvious problems with having
> cached data that a user would believe is no longer cached and which could
> thus expose all kinds of private data.
>
> Ciao,
>
> Dre
>
> Waldo Bastian wrote:
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA1
> >
> > FYI
> >
> > George Staikos pointed out that KMail probably never really exits in this
> > scenario and that "restarting kmail" most likely just re-uses the still
> > running instance thanks to KUniqueApplication.

- -- 
bastian@kde.org -=|[ SUSE, The Linux Desktop Experts ]|=- bastian@suse.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQFAL9NxN4pvrENfboIRAvvyAJ9ngpS+de5Q55mKpxTrMWWutEpUnwCgjsHc
AGd2RaEQ9l9JDzQAawIaC2E=
=RmmU
-----END PGP SIGNATURE-----
_______________________________________________
KMail developers mailing list
KMail-devel@kde.org
https://mail.kde.org/mailman/listinfo/kmail-devel

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic