Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Deletion of important flash_player config files by flash-plugin #107

Closed
hlef opened this issue Oct 14, 2015 · 3 comments
Closed

Deletion of important flash_player config files by flash-plugin #107

hlef opened this issue Oct 14, 2015 · 3 comments
Labels
Milestone

Comments

@hlef
Copy link

hlef commented Oct 14, 2015

Hi,
I'm bleachbit's Debian Maintainer.

Today I've received the following bug (also available online here):


Dear Maintainer,

  • What led up to the situation?
    If one enables deleting temp files of the flash-plugin then also the config-file of the flash-plugin gets deleted.
  • What exactly did you do (or not do) that was effective (or ineffective)?
    I had enabled deleting of the undesired flash files (cookies, tmp files etc.)
  • What was the outcome of this action?
    It deleted also the (binary) config file: ~/.macromedia/Flash_Player/macromedia.com/support/flashplayer/sys/settings.sol
  • What outcome did you expect instead?
    It should not delete that file, because that is a config file, and if it is not existent, then the defaults apply, and that leads to severe security issues, because if one had tightened the security of the flash-plugin, then these security settings will silently be gone by deleting the said file. So, the said file should be not deleted by this otherwise useful program.

Please, notice that this bug have been reported against bleachbit's version 1.4, currently available on Debian Jessie.

I haven't reproduced this bug on later versions (lack of time, sorry). I've decided to directly forward the bug since it may be a security issue.

Thanks for your work,
Hugo

@az0 az0 added this to the 1.10 milestone Oct 14, 2015
@az0
Copy link
Member

az0 commented Oct 14, 2015

I will check into it.

@az0 az0 added the bug label Oct 14, 2015
@az0
Copy link
Member

az0 commented Dec 3, 2015

I mostly manage in Launchpad, so I posted it here

https://bugs.launchpad.net/bleachbit/+bug/1522243

@az0
Copy link
Member

az0 commented Mar 25, 2016

This file also contains a list of domain names that has been visited and that use Flash. You can check it yourself by running

strings ~/.macromedia/Flash_Player/macromedia.com/support/flashplayer/sys/settings.sol

So some people want to delete this file.

The user has several options, including:

  1. Not use the Adobe Flash cleaner
  2. Use the whitelist functionality through the Preferences menu
  3. Edit flash.xml to white-list just this file using the old nregex filter or new nwholeregex filter

@az0 az0 closed this as completed Mar 25, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants