Bug#656378: iceweasel: System-wide extensions (in /usr/share/) should be trusted by default

Witold Baryluk baryluk at smp.if.uj.edu.pl
Wed Jan 18 21:31:27 UTC 2012


Package: iceweasel
Version: 9.0.1-1
Severity: normal

Hi,

after upgrading iceweasel of some extensions, an iceweasel asks again user if
he/she wants to use and trust each extension fro /usr/share directory. I think
it is redundant, and such question should be not asked (/usr/share should be
equivalent
to whitelisted and secured source of extension). This is particulary troubeling
currently, because updating iceweasel or its extensions is independent fro
using iceweasel, so after upgrading iceweasel or extension (especially because
of secuirty updates), it may make user show randomly (for him) monits about if
he/she wants to trust extensions.

Just whitelist /usr/share/* and /usr/local/share/* or whetever subdirectories
are needed for this to work without unacassary monits.

Thanks.



-- Package-specific info:

-- Extensions information
Name: CSS Validator extensionfalse
Location: ${PROFILE_EXTENSIONS}/{AB7308B2-C13C-4eba-AC78-2AD55B96EE09}
Status: app-disabled

Name: DOM Inspector extensionfalse
Location: /usr/share/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}/inspector at mozilla.org
Package: xul-ext-dom-inspector
Status: enabled

Name: Default themefalse
Location: /usr/lib/iceweasel/extensions/{972ce4c6-7e08-4474-a285-3208198ce6fd}
Package: iceweasel
Status: enabled

Name: FireUnit extensionfalse
Location: ${PROFILE_EXTENSIONS}/fireunit at mozilla.com
Status: app-disabled

Name: Firebug extensionfalse
Location: ${PROFILE_EXTENSIONS}/firebug at software.joehewitt.com
Status: app-disabled

Name: FirefoxNotify extensionfalse
Location: /usr/share/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}/firefoxnotify at abhishek.mukherjee
Package: xul-ext-notify
Status: app-disabled

Name: Flashblock extensionfalse
Location: /usr/share/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}/{3d7eb24f-2740-49df-8937-200b1cc08f8a}
Package: xul-ext-flashblock
Status: enabled

Name: Greasemonkey extensionfalse
Location: /usr/share/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}/{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
Package: xul-ext-greasemonkey
Status: enabled

Name: Html Validator extensionfalse
Location: ${PROFILE_EXTENSIONS}/{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}
Status: app-disabled

Name: Polski Language Pack localefalse
Location: /usr/lib/iceweasel/extensions/langpack-pl at firefox.mozilla.org.xpi
Package: iceweasel-l10n-pl
Status: enabled

Name: Relaxed the HTML Validator extensionfalse
Location: ${PROFILE_EXTENSIONS}/relaxed at vse.cz
Status: app-disabled

Name: ShowIP extensionfalse
Location: ${PROFILE_EXTENSIONS}/{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi
Status: user-disabled

-- Plugins information
Name: DivX® Web Player
Location: /usr/lib/mozilla/plugins/libtotem-mully-plugin.so
Package: totem-mozilla
Status: enabled

Name: Gnome Shell Integration
Location: /usr/lib/mozilla/plugins/libgnome-shell-browser-plugin.so
Package: gnome-shell
Status: enabled

Name: QuickTime Plug-in 7.6.6
Location: /usr/lib/mozilla/plugins/libtotem-narrowspace-plugin.so
Package: totem-mozilla
Status: enabled

Name: Shockwave Flash
Location: /usr/lib/flashplugin-nonfree/libflashplayer.so
Status: enabled

Name: Skype Buttons for Kopete
Location: /usr/lib/mozilla/plugins/skypebuttons.so
Package: kopete
Status: enabled

Name: VLC Multimedia Plugin (compatible Totem 3.0.1)
Location: /usr/lib/mozilla/plugins/libtotem-cone-plugin.so
Package: totem-mozilla
Status: enabled

Name: Windows Media Player Plug-in 10 (compatible; Totem)
Location: /usr/lib/mozilla/plugins/libtotem-gmp-plugin.so
Package: totem-mozilla
Status: enabled

Name: iTunes Application Detector
Location: /usr/lib/mozilla/plugins/librhythmbox-itms-detection-plugin.so
Package: rhythmbox-plugins
Status: enabled


-- Addons package information
ii  gnome-shell    3.2.1-8        graphical shell for the GNOME desktop
ii  iceweasel      9.0.1-1        Web browser based on Firefox
ii  iceweasel-l10n 1:9.0+debian-1 Polish language package for Iceweasel
ii  kopete         4:4.6.5-3      instant messaging and chat application
ii  rhythmbox-plug 2.95-1         plugins for rhythmbox music player
ii  totem-mozilla  3.0.1-6        Totem Mozilla plugin
ii  xul-ext-dom-in 1:2.0.10-1     tool for inspecting the DOM of pages in Icew
ii  xul-ext-flashb 1.5.15-1       mozilla extension to block Adobe Flash conte
ii  xul-ext-grease 0.9.13-1       extension that enables customization of webp
ii  xul-ext-notify 1.5.4-4        integrate Iceweasel/Firefox download message

-- System Information:
Debian Release: wheezy/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 3.1.0-1-686-pae (SMP w/1 CPU core)
Locale: LANG=pl_PL.UTF-8, LC_CTYPE=pl_PL.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages iceweasel depends on:
ii  debianutils         4.1
ii  fontconfig          2.8.0-3
ii  libc6               2.13-24
ii  libgdk-pixbuf2.0-0  2.24.0-2
ii  libglib2.0-0        2.30.2-4
ii  libgtk2.0-0         2.24.8-2
ii  libnspr4-0d         4.8.9-1
ii  libstdc++6          4.6.2-11
ii  procps              1:3.3.2-2
ii  xulrunner-9.0       9.0.1-1

iceweasel recommends no packages.

Versions of packages iceweasel suggests:
ii  libgssapi-krb5-2    1.10+dfsg~beta1-2
ii  mozplugger          <none>
ii  ttf-lyx             2.0.2-1
ii  ttf-mathematica4.1  <none>
ii  xfonts-mathml       4

Versions of packages xulrunner-9.0 depends on:
ii  libasound2                1.0.24.1-4
ii  libatk1.0-0               2.2.0-2
ii  libbz2-1.0                1.0.6-1
ii  libc6                     2.13-24
ii  libcairo2                 1.10.2-6.2
ii  libdbus-1-3               1.4.16-1
ii  libevent-2.0-5            2.0.16-stable-1
ii  libfontconfig1            2.8.0-3
ii  libfreetype6              2.4.8-1
ii  libgcc1                   1:4.6.2-11
ii  libgdk-pixbuf2.0-0        2.24.0-2
ii  libglib2.0-0              2.30.2-4
ii  libgtk2.0-0               2.24.8-2
ii  libhunspell-1.3-0         1.3.2-4
ii  libjpeg8                  8c-2
ii  libmozjs9d                9.0.1-1
ii  libnotify4                0.7.4-1
ii  libnspr4-0d               4.8.9-1
ii  libnss3-1d                3.13.1.with.ckbi.1.88-1
ii  libpango1.0-0             1.29.4-2
ii  libpixman-1-0             0.24.0-1
ii  libreadline6              6.2-8
ii  libsqlite3-0              3.7.9-2
ii  libstartup-notification0  0.12-1
ii  libstdc++6                4.6.2-11
ii  libvpx0                   0.9.7.p1-2
ii  libx11-6                  2:1.4.4-4
ii  libxext6                  2:1.3.0-3
ii  libxrender1               1:0.9.6-2
ii  libxt6                    1:1.1.1-2
ii  zlib1g                    1:1.2.3.4.dfsg-3

Versions of packages xulrunner-9.0 suggests:
ii  libcanberra0      0.28-3
ii  libdbus-glib-1-2  0.98-1
ii  libgnomeui-0      2.24.5-2

-- debconf-show failed





More information about the pkg-mozilla-maintainers mailing list