    2 See user/1002/README for general remarks on risks with image viewers.
    4 This protection is needed only if you use gimp to manipulate untrusted
    5 pictures, for example those coming from untrusted network sources.
    7 The file access rights are defined only for gimp-1.2. You must change the
    8 directory names if you have a different version.
   10 File write access is not restricted in this token, because normally gimp
   11 needs wide write accesses. This is VERY unsatisfactory; to have a really
   12 secure execution of gimp, you need to make a modified definition with
   13 restricted read/write accesses.