Package: flatpak-builder
Version: 1.4.10-1
Severity: grave
Tags: security help
Justification: user security hole
X-Debbugs-Cc: Debian Security Team <[email protected]>

https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv

If flatpak-builder is run against an untrusted manifest and the manifest 
specifies `use-git-am: true`, a malicious module source can trigger 
arbitrary code execution on the host system by adding a 
`post-applypatch` hook.

I'm erring on the side of caution and reporting this as grave, but it 
can maybe be downgraded to important since most people only build 
Flatpak apps whose manifest they have written (or at least, had the 
opportunity to audit) themselves. It's mainly a serious problem for 
repository-as-a-service providers that accept untrusted apps for 
building, like Flathub.

If this needs fixing in trixie, either with a DSA or in a point release, 
I'd appreciate help. (Felix, would you be able to take this one?)

    smcv

Reply via email to