Re: Packages providing Flatpak sandbox escapes via vulnerable MIME Type Handler

Michael Catanzaro via devel <[email protected]>
Newsgroups gmane.linux.redhat.fedora.devel
Message-ID <[email protected]>
Keep in mind the portals are used not only by Flatpak, but also snap and WebKitGTK.

The portal *could* choose to require user interaction before launching a file, but probably users will just click Allow and lose, so that doesn't seem like a great solution. Also, that would likely become seriously annoying pretty quickly.

The security warning is hidden in the COMMANDS section of the man page, under the "default" command.

-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.