[Bug 280397] New: Installing packages via konqueror uses different installation source
https://bugzilla.novell.com/show_bug.cgi?id=280397 Summary: Installing packages via konqueror uses different installation source Product: openSUSE 10.3 Version: Alpha 4plus Platform: i386 OS/Version: openSUSE 10.3 Status: NEW Severity: Major Priority: P5 - None Component: KDE AssignedTo: kde-maintainers@suse.de ReportedBy: gp@novell.com QAContact: qa@suse.de CC: security-team@suse.de I believe this actually is a security problem, because the user may inadvertedly obtain a different and older version (potentially with known vulnerabilities) of the package than she thinks she is getting. Thus marking this major and Cc:ing security-team. At http://w3.suse.de/~gp/fate-1.3.6-9.1.i586.rpm I have a newly built version of Fate which I'd like to install. So, once I am at the appropriate screen in konqueror (screenshot will follow), I choose "Install Package with YaST". Alas, the system install a version of the package from my regular installion sources, *not* the one I viewed in konqueror! -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=280397 ------- Comment #1 from gp@novell.com 2007-06-03 15:11 MST ------- Created an attachment (id=143794) --> (https://bugzilla.novell.com/attachment.cgi?id=143794&action=view) Screenshot of the respective display in konqueror -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=280397 dmueller@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |NEEDINFO Info Provider| |gp@novell.com ------- Comment #2 from dmueller@novell.com 2007-06-04 03:07 MST ------- can you try bash -x /opt/kde3/share/apps/krmpview/setup_temp_source /path/to/fate.rpm ? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=280397 gp@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |RESOLVED Info Provider|gp@novell.com | Resolution| |WORKSFORME ------- Comment #3 from gp@novell.com 2007-06-06 05:43 MST ------- This is very emabarrasing. Originally I reproduced this twice to make sure, but currently (which is after another update to STABLE on this machine and some changes to installatoin sources ) I am no longer able to do so, despite several attempts with different settings. :-( I am thus closing this as WORKSFORME and will try to keep an eye on this. If this pops up again, I will provide the requested log right away! -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
participants (1)
-
bugzilla_noreply@novell.com