Ubuntu ‘Command Not Found’ Open to Exploit with Snaps
Researchers at Aqua Security say they’ve discovered a significant security issue with Ubuntu’s “command not found” feature. When you run a command for a package not installed Ubuntu’s “command not found” feature kicks in to tell you a) command not found and b) proactively suggests the relevant package(s) you need to install to run the command you tried. Packages recommendations are drawn from DEB software available in the Ubuntu repos (queried against a local database that doesn’t change often), and for snap packages on the Snap Store (which involves connecting to the store’s online database). Using snaps, security researchers say […]
You're reading Ubuntu ‘Command Not Found’ Open to Exploit with Snaps, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.