brave / browser-laptop

[DEPRECATED] Please see https://github.com/brave/brave-browser for the current version of Brave
https://www.brave.com
Other
7.95k stars 975 forks source link

CVE-2018-20483 aka user.xdg.origin.url #15344

Closed rastislavcore closed 5 years ago

rastislavcore commented 5 years ago

Troubleshooting checklist

There's a good chance the bug you're about to report is fixed in the new version of Brave

If you'd like to continue for this old version, please check the applicable items:

Description

Downloaded files are saving URLs from which are downloaded into «user.xdg.origin.url» or «user.xdg.referrer.url»

Steps to Reproduce

  1. Download file
  2. Read with getfattr
  3. Check if file contain location from which was downloaded

What version of Brave are you using?

Version 0.58.17 Chromium: 71.0.3578.98 (Official Build) (64-bit)

bsclifton commented 5 years ago

Closing in favor of https://github.com/brave/brave-browser/issues/2766 which is tracking this in the new repo

@raisty can you please add some additional info in that version of the issue? Thanks! 😄