Files moved to "Exclude"ed folders still exist in Dash

Bug #1477787 reported by TenLeftFingers
268
This bug affects 4 people
Affects Status Importance Assigned to Milestone
Unity
Confirmed
Low
Unassigned
unity (Ubuntu)
Confirmed
Low
Unassigned

Bug Description

Go to System Settings -> Security & Privacy -> Files & Applications
Add the Public directory to the Exclude list.

Now choose a document that shows up in the dash.
Move that document to the Public directory.
Open the dash.

Expected:
File is no longer visible or searchable in the dash

Actual:
File is visible in dash.
"Show in Folder" opens the Public directory, revealing the file.

Marking this as a security issue as it's part of the Security & Privacy settings.

Revision history for this message
Tyler Hicks (tyhicks) wrote :

I can confirm this on Wily. If you click "clear the usage data" from the Security & Privacy, then the document no longer shows up in the dash but it seems like adding an excluded directory does not cause the cache to be invalidated.

I don't see how this could allow attackers to cross privilege boundaries or directly cause loss of data/privacy so I'm going to go ahead and make this public so that more developers can have access to the report.

Changed in unity-control-center (Ubuntu):
status: New → Confirmed
importance: Undecided → Low
information type: Private Security → Public Security
affects: unity-control-center (Ubuntu) → unity (Ubuntu)
Changed in unity:
importance: Undecided → Low
status: New → Confirmed
Revision history for this message
Seth Johnson (sethj) wrote :

As part of the big bug review for 16.04 LTS I have tested this on 15.10 and the bug is still there.

tags: added: desktop-bugscrub-triaged
Revision history for this message
Douglas (douglaslawrence) wrote :

As part of the big bug review for 16.04 LTS I have tested this on 15.10 and the bug is still there.

Revision history for this message
Rodrigo Lledó (rodhos-hp) wrote :

As part of the big bug review for 16.04 LTS, I have tested this on 15.10 and the bug is still there.

Revision history for this message
karthikkn (karthikkn) wrote :

As part of the big bug review for 16.04 LTS, I have tested this on 15.10 and the bug is still there.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.