Comment 7 for bug 1899193

Revision history for this message
Julian Andres Klode (juliank) wrote :

I'm now also looking into where aptd opens those files in the first place, and how we can move the PolicyKit check before that, as we really don't want untrusted users to be able to parse/decompress random files in a root process, which happens if it's reading the deb.