Supply Chain Vulnerabilities found and fixed in Fedora's Pagure and openSUSE's Open Build Service (fenrisk.com)
from that_leaflet@lemmy.world to linux@lemmy.ml on 19 Mar 16:48
https://lemmy.world/post/27055870

#linux

threaded - newest

LordPassionFruit@lemm.ee on 19 Mar 16:57 next collapse

I’ve tried reading through the article, but unfortunately, I’m not the sharpest tool in the shed. I use openSUSE, how does this affect me, and what do I need to do/what can I do about this?

that_leaflet@lemmy.world on 19 Mar 16:59 next collapse

You don’t need to do anything, these issues have already been fixed.

LordPassionFruit@lemm.ee on 19 Mar 17:08 next collapse

Perfect. Thank you for taking the time to respond

blackbrook@mander.xyz on 20 Mar 02:16 collapse

Do you mean the specific exploit performed by the author has been fixed? Or the general vulnerability that this exploit was intended to demonstrate has been fixed? The article ends with a What’s Next section discussing the difficulty of the latter, saying

we don’t think there’s a silver bullet to address the risks caused by the compromise of such central pieces of infrastructure

and going into detail about the challenges for openSUSE OBS. Are you claiming those challenges have all been solved and exploits like this are no longer possible?

that_leaflet@lemmy.world on 20 Mar 10:45 collapse

The authors found and reported vulnerabilities in Pagure and Open Build Service. These vulnerabilities have since been fixed.

JustAnotherKay@lemmy.world on 19 Mar 18:34 collapse

Usually with vulnerabilities like this, they’re not gonna say anything about it until after they patch it so that people don’t go abuse it

blackbrook@mander.xyz on 20 Mar 02:08 next collapse

Supply chain attacks have been a trendy topic in the past years.

Has the meaning of ‘trendy’ changed from what I’m used to?

FauxLiving@lemmy.world on 20 Mar 14:13 collapse

It’s 2024, if you’re not exploiting CI systems to inject your malware into the dependency chain for large open source projects, what even are you doing with your life?

cypherpunks@lemmy.ml on 20 Mar 15:20 collapse

it’s 2025 now but otherwise yeah

FauxLiving@lemmy.world on 20 Mar 15:59 collapse

Not according to my, completely malware free, waybar-git-real!

cypherpunks@lemmy.ml on 20 Mar 15:52 collapse

Nice post, but your title is misleading: the blog post is actually titled “Supply Chain Attacks on Linux distributions - Overview” - the word “attacks” as used here is a synonym for “vulnerabilities”. It is not completely clear from their title if this is going to be a post about vulnerabilities being discovered, or about them actually being exploited maliciously, but the latter is at least not strongly implied.

This lemmy post however is titled (currently, hopefully OP will retitle it after this comment) “Supply Chain Attack found in Fedora’s Pagure and openSUSE’s Open Build Service”. edit: @OP thanks for changing the title!

Adding the word “found” (and making “Attack” singular) changes the meaning: this title strongly implies that a malicious party has actually been detected performing a supply chain attack for real - which is not what this post is saying at all. (It does actually discuss some previous real-world attacks first, but it is not about finding those; the new findings in this post are vulnerabilities which were never attacked for real.)

I recommend using the original post title (minus its “Overview” suffix) or keeping your more verbose title but changing the word “Attack” to “Vulnerabilities” to make it clearer.

TLDR: These security researchers went looking for supply chain vulnerabilities, and found several bugs in two different systems. After responsibly disclosing them, they did these (very nice and accessible, btw - i recommend reading them) writeups about two of the bugs. The two they wrote up are similar in that they both involve going from being able to inject command line arguments, to being able to write to a file, to being able to execute arbitrary code (in a context which would allow attackers to perform supply chain attacks on any software distributed via the targeted infrastructure).

bastion@feddit.nl on 22 Mar 02:00 collapse

yeah, it turns the thing into clickbait.