Re: Security Problem with "PackageKit-command-not-found" package

2022-08-25 Thread Sandipan Roy
Some CVEs are appeared because of this issue, Details + Analysis found at: https://sysdream.com/abusing-packagekit-fedora-centos-for/ ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.o

Re: Security Problem with "PackageKit-command-not-found" package

2022-08-25 Thread Sandipan Roy
Wheel user rule for packagekit $ sudo cat /usr/share/polkit-1/rules.d/org.freedesktop.packagekit.rules [sudo] password for sandipan: polkit.addRule(function(action, subject) { if ((action.id == "org.freedesktop.packagekit.package-install" || action.id == "org.freedesktop.packagekit.p

Security Problem with "PackageKit-command-not-found" package

2022-08-25 Thread Sandipan Roy
Hello World, I'm Sandipan Roy [FAS: ByteHackr], I wanted to share a serious system wide problem with PackageKit-command-not-found [1] package. Can you guys give some feedback if I can submit a system wide change proposal to remove this because its a poor system design. By this vulnerab