Local users get to play root?
Richard Hughes
hughsient at gmail.com
Thu Nov 19 14:22:21 UTC 2009
2009/11/19 Chris Adams <cmadams at hiwaay.net>:
> Once upon a time, Ricky Zhou <ricky at fedoraproject.org> said:
>> I might be wrong on this, but wouldn't the attacker need to trick
>> yum/packagekit into using the malicious repo first? I didn't think that
>> was allowed for non-root users.
>
> 1.5 words: NetworkManager. Think about it.
2 words: Package signing.
If the key is different to the one that was preciously imported, you
need the root password.
Richard.
More information about the fedora-devel-list
mailing list