GTKhash flaw that affects also Thunar-gtkhash

The flaw interferes with the clipboard and text files (even Qubes clipboard)

How to reproduce!

  1. Install thunar-gtkhash in Whonix (it probably affects all Linux)
    sudo apt install thunar-gtkhash
  2. Download the checksums for a nightly release of and write on a piece of paper.
    Of course this is no accident because they used some uncommon hashes.
  3. Download Pentoo (scurl-download https://…) and use thunar-gtkhash. Open with Mousepad the hash file.
    Copy and paste the hash from thunar-gtkhash under the hash provided in the text file.
    They shoud be different of what you have on the piece of paper but the same in the text file.