VirtualBox

Ticket #9041 (new defect)

Opened 3 years ago

Last modified 3 years ago

The example python script src/VBox/Frontends/VBoxShell/vboxshell.py

Reported by: dab Owned by:
Priority: minor Component: documentation
Version: VirtualBox 4.0.4 Keywords:
Cc: Guest type: other
Host type: Linux

Description (last modified by frank) (diff)

The example python script src/VBox/Frontends/VBoxShell/vboxshell.py, has the ability to save screen-shots. When no file-name for a screen-shot the takeScreenshot function writes the screen-shot to "/tmp/screenshot.png". Potentially "/tmp/screenshot.png" could be a symbolic link to another file. The other file would be over-written if a user saved a screen-shot without specifying the file-name.

Change History

comment:1 Changed 3 years ago by frank

  • Description modified (diff)

That is correct but only a minor issue and definitely not a security issue, perhaps rather a not-so-obvious behavior.

comment:2 Changed 3 years ago by dab

Sure, it isn't a real security issue - just some avoidable silliness.

Note: See TracTickets for help on using tickets.

www.oracle.com
ContactPrivacy policyTerms of Use