[kdenetwork-filesharing] [Bug 466786] "make me a group member" button didn't work because the samba user shares group didn't contain the text "samba", but this wasn't mentioned anywhere

Harald Sitter bugzilla_noreply at kde.org
Fri Mar 10 19:43:14 GMT 2023


https://bugs.kde.org/show_bug.cgi?id=466786

--- Comment #26 from Harald Sitter <sitter at kde.org> ---
This call here
https://invent.kde.org/network/kdenetwork-filesharing/-/blob/master/samba/filepropertiesplugin/groupmanager.cpp#L120
may be made by any application that has access to the bus. They may request
becoming member of any group because of how the function works. The only thing
standing between a malicious application making this request to push the user
into the wheel group or root group or admin group and then exploit the access
that comes with that is the group filtering.

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the Unassigned-bugs mailing list