- cross-posted to:
- security@programming.dev
- cross-posted to:
- security@programming.dev
Aqua Nautilus researchers have identified a security issue that arises from the interaction between Ubuntu’s command-not-found package and the snap package repository. While command-not-found serves as a convenient tool for suggesting installations for uninstalled commands, it can be inadvertently manipulated by attackers through the snap repository, leading to deceptive recommendations of malicious packages.
This isn’t the point of the review. Verified apps only say this is the application as offered by the original vendor.
If the original vendor were to bundle malware, then that’s a bad vendor, but still verified official software. Not that I actually think this will happen. Most user install malware such as Discord willingly. /j