[Touch-packages] [Bug 1893241] Re: attack alias sudo with nasty payload

2020-08-29 Thread Patrik Nilsson
@seth-arnold I agree with you that there are other things to address as well. In the art of hacking you most probably get into a system via some kind of service. You maybe have the privileges of a daemon. You then get an access to the first user account. You want to escalate privilege and you

[Touch-packages] [Bug 1893241] Re: attack alias sudo with nasty payload

2020-08-28 Thread Seth Arnold
Hello Patrik, thanks for your concern for Ubuntu's security. As you said, there are numerous possibilities for trouble when an account is compromised in this fashion. Placing malicious versions of utilities into ~/bin is another common choice. (Usually shell aliases, functions, and ~/bin/

[Touch-packages] [Bug 1893241] Re: attack alias sudo with nasty payload

2020-08-28 Thread Seth Arnold
** Information type changed from Private Security to Public Security ** Changed in: bash (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to bash in Ubuntu.