Updates tab automatically loads hacked website

Bug #1179127 reported by Luci Sandor
16
This bug affects 3 people
Affects Status Importance Assigned to Milestone
acetoneiso (Debian)
Fix Released
Unknown
acetoneiso (Ubuntu)
Fix Released
Undecided
Nick Andrik

Bug Description

The Updates tab connnects to the internet automatically, and downloads a page (presumably acetoneteam.org). Worse than the loss of privacy, the page is now peddling scareware, saying that the users need to Update flash player to the non-existent version 12, with a modal dialog. The bug has been reported upstream.

Luci Sandor (lucisandor)
information type: Private Security → Public
Changed in acetoneiso (Debian):
status: Unknown → Fix Released
Nick Andrik (andrikos)
Changed in acetoneiso (Ubuntu):
assignee: nobody → Nick Andrik (andrikos)
status: New → Confirmed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package acetoneiso - 2.4-1

---------------
acetoneiso (2.4-1) unstable; urgency=low

  * New upstream release
    - converted genisoimage to xorriso for "Folder to ISO" feature
    - default KDE file manager now set to dolphin, removed kmfclient usage
    - fixed youtube-dl "-b" option not working anymore
    - fixed issue when mounting in an a generic folder [reported by
      Jack Bauer]
    - ensure gpg2 is installed, bug ticket about gpg2
      https://bugs.launchpad.net/ubuntu/+source/gnupg2/+bug/659509
    - removed phonon dependency
    - updated Russian translation [Thanks to Oleg Koptev]
    - added Spanish translation [Thanks to Otniel Watanabe]
    - UI changes, disabled all incomplete features (burning, torrent) and
      disabled updates tab

  * Translations
    - update Portuguese Brazilian translation (Closes: #715318)
    - include new translations from Launchpad (2013-11-14)
    - fix untranslated strings that were shown as empty (Closes: #728829,
      LP: #1220868)
  * Remove references to defunct homepage (Closes: #706741, LP: #1179127)
  * Update the copyright file to include all HTML manuals
  * Allow build for any architecture (it was linux-any)
  * Bump standards version to 3.9.5
  * Added VCS links
  * Added Categories entry to .desktop file

 -- Nick Andrik <email address hidden> Sun, 17 Nov 2013 05:05:08 +0100

Changed in acetoneiso (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.