124
submitted 9 months ago by pnutzh4x0r@lemmy.ndlug.org to c/linux@lemmy.ml

Aqua Nautilus researchers have identified a security issue that arises from the interaction between Ubuntu’s command-not-found package and the snap package repository. While command-not-found serves as a convenient tool for suggesting installations for uninstalled commands, it can be inadvertently manipulated by attackers through the snap repository, leading to deceptive recommendations of malicious packages.

you are viewing a single comment's thread
view the rest of the comments
[-] octopus_ink@lemmy.ml 2 points 9 months ago* (last edited 9 months ago)

I suppose that sounds great, but every time I see a thread where folks complain about these various packaging formats, I'm just really happy I don't use any of them on my system. All I see in these discussions are user-level problems that I don't ever have due to avoiding them entirely. One day when I can't run a distro that doesn't use them I suppose I'll have no choice, but until then... We clearly seem NOT to have settled on a single target, so I don't know why I'd voluntarily wade into all that as a user while it's still not settled.

this post was submitted on 14 Feb 2024
124 points (97.0% liked)

Linux

48376 readers
810 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 5 years ago
MODERATORS