360: Oh Snap! Command Not Found vulnerability found

Originally published at: https://tuxdigital.com/podcasts/destination-linux/dl-360/

When I read the aquasec article, it doesn’t sound like they are talking about either the apt command or apt-get and friends. To me it sounds like they are saying that within the command-not-found database that 26% of the apt packages listed don’t have a corresponding snap package that either exists or is claimed by someone.

They are saying that for those cases, the door is open for someone to upload a malicious snap package, that has the same name as a deb package.

