{"id":24512,"date":"2017-07-28T17:03:21","date_gmt":"2017-07-28T09:03:21","guid":{"rendered":"https:\/\/www.deepin.org\/?p=24512"},"modified":"2017-09-05T14:03:47","modified_gmt":"2017-09-05T06:03:47","slug":"deepin-security-update-urgently-fixed-bad-taste-security-vulnerability-cve-2017-11421-in-gnome-files","status":"publish","type":"post","link":"https:\/\/www.deepin.org.cn\/en\/deepin-security-update-urgently-fixed-bad-taste-security-vulnerability-cve-2017-11421-in-gnome-files\/","title":{"rendered":"Deepin Security Update\u2014\u2014Urgently Fixed Bad Taste Security vulnerability CVE-2017-11421 in GNOME Files"},"content":{"rendered":"<img loading=\"lazy\" class=\"aligncenter size-full wp-image-24522\" src=\"https:\/\/www.deepin.org\/wp-content\/uploads\/2017\/07\/en-6.jpg\" alt=\"en\" width=\"749\" height=\"321\" srcset=\"https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6.jpg 749w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6-600x257.jpg 600w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6-150x64.jpg 150w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6-300x129.jpg 300w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6-24x10.jpg 24w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6-36x15.jpg 36w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6-48x21.jpg 48w\" sizes=\"(max-width: 749px) 100vw, 749px\" \/><\/p>\n<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-24522\" src=\"https:\/\/www.deepin.org\/wp-content\/uploads\/2017\/07\/en-6.jpg\" alt=\"en\" width=\"749\" height=\"321\" srcset=\"https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6.jpg 749w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6-600x257.jpg 600w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6-150x64.jpg 150w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6-300x129.jpg 300w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6-24x10.jpg 24w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6-36x15.jpg 36w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en-6-48x21.jpg 48w\" sizes=\"(max-width: 749px) 100vw, 749px\" \/><\/p>\n<p>The security updates of Bad Taste (gnome-exe-thumbnailer).<\/p>\n<p>&nbsp;<\/p>\n<h2><b>Vulnerability Information<\/b><\/h2>\n<p><strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-11421\">CVE-2017-11421<\/a> \u2014<strong><strong><strong>Security Updates<\/strong><\/strong><\/strong><\/strong><\/p>\n<p>Security database details:<\/p>\n<p>gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the \"Bad Taste\" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its filename.<\/p>\n<p>&nbsp;<\/p>\n<h2>Fixing Status<\/h2>\n<p>gnome-exe-thumbnailer security vulnerabilities have been fixed in deepin 15.4.1 updates\uff0820170727\uff09.<\/p>\n<p>We recommend that you upgrade the system to obtain the patches to fix the vulnerabilities.<\/p>\n<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-24523\" src=\"https:\/\/www.deepin.org\/wp-content\/uploads\/2017\/07\/en_s-4.jpg\" alt=\"en_s\" width=\"187\" height=\"96\" srcset=\"https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en_s-4.jpg 187w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en_s-4-150x77.jpg 150w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en_s-4-24x12.jpg 24w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en_s-4-36x18.jpg 36w, https:\/\/www.deepin.org.cn\/wp-content\/uploads\/2017\/07\/en_s-4-48x25.jpg 48w\" sizes=\"(max-width: 187px) 100vw, 187px\" \/>","protected":false},"excerpt":{"rendered":"<p>The security updates of Bad Taste (gnome-exe-thumbnailer). &nbsp; Vulnerability Information CVE-2017-11421 \u2014Security Updates Security database details: gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the \"Bad Taste\" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its filename. &nbsp; Fixing Status gnome-exe-thumbnailer security vulnerabilities have been fixed in deepin 15.4.1 updates\uff0820170727\uff09. We recommend that you upgrade the system to obtain the patches to fix the vulnerabilities.<\/p>\n","protected":false},"author":141,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[75,93],"tags":[],"_links":{"self":[{"href":"https:\/\/www.deepin.org.cn\/en\/wp-json\/wp\/v2\/posts\/24512"}],"collection":[{"href":"https:\/\/www.deepin.org.cn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.deepin.org.cn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.deepin.org.cn\/en\/wp-json\/wp\/v2\/users\/141"}],"replies":[{"embeddable":true,"href":"https:\/\/www.deepin.org.cn\/en\/wp-json\/wp\/v2\/comments?post=24512"}],"version-history":[{"count":15,"href":"https:\/\/www.deepin.org.cn\/en\/wp-json\/wp\/v2\/posts\/24512\/revisions"}],"predecessor-version":[{"id":25408,"href":"https:\/\/www.deepin.org.cn\/en\/wp-json\/wp\/v2\/posts\/24512\/revisions\/25408"}],"wp:attachment":[{"href":"https:\/\/www.deepin.org.cn\/en\/wp-json\/wp\/v2\/media?parent=24512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.deepin.org.cn\/en\/wp-json\/wp\/v2\/categories?post=24512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.deepin.org.cn\/en\/wp-json\/wp\/v2\/tags?post=24512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}