Bug 487791 - plasma-discover: permission grant user to act as root
Summary: plasma-discover: permission grant user to act as root
Status: RESOLVED WORKSFORME
Alias: None
Product: Discover
Classification: Applications
Component: discover (show other bugs)
Version: unspecified
Platform: Other Linux
: NOR major
Target Milestone: ---
Assignee: Plasma Bugs List
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-05-30 12:01 UTC by Marco Righi
Modified: 2024-06-29 03:47 UTC (History)
1 user (show)

See Also:
Latest Commit:
Version Fixed In:
Sentry Crash Report:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marco Righi 2024-05-30 12:01:43 UTC
SUMMARY


STEPS TO REPRODUCE
1.  ls -l $(which plasma-discover)


OBSERVED RESULT
452K -rwxr-xr-x 1 root root 450K 25 mag 22.42 /usr/bin/plasma-discover


EXPECTED RESULT
452K -rwx------ 1 root root 450K 25 mag 22.42 /usr/bin/plasma-discover


SOFTWARE/OS VERSIONS

Linux/KDE Plasma: 
(available in About System)
LSB Version:	n/a
Distributor ID:	EndeavourOS
Description:	EndeavourOS Linux
Release:	rolling
Codename:	rolling


KDE Plasma Version: 

plasmashell --version
plasmashell 6.0.5

KDE Frameworks Version: 


Qt Version: 
qmake --version
QMake version 3.1
Using Qt version 5.15.14 in /usr/lib

ADDITIONAL INFORMATION
Same security problem on Linux Manjaro

lsb_release -a
LSB Version:	n/a
Distributor ID:	ManjaroLinux
Description:	Manjaro Linux
Release:	24.0.1
Codename:	Wynsdey
Comment 1 Antonio Rojas 2024-05-30 12:30:19 UTC
Why is it a security issue to allow users to run Discover?
Comment 2 Bug Janitor Service 2024-06-14 03:47:15 UTC
Dear Bug Submitter,

This bug has been in NEEDSINFO status with no change for at least
15 days. Please provide the requested information as soon as
possible and set the bug status as REPORTED. Due to regular bug
tracker maintenance, if the bug is still in NEEDSINFO status with
no change in 30 days the bug will be closed as RESOLVED > WORKSFORME
due to lack of needed information.

For more information about our bug triaging procedures please read the
wiki located here:
https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging

If you have already provided the requested information, please
mark the bug as REPORTED so that the KDE team knows that the bug is
ready to be confirmed.

Thank you for helping us make KDE software even better for everyone!
Comment 3 Bug Janitor Service 2024-06-29 03:47:38 UTC
This bug has been in NEEDSINFO status with no change for at least
30 days. The bug is now closed as RESOLVED > WORKSFORME
due to lack of needed information.

For more information about our bug triaging procedures please read the
wiki located here:
https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging

Thank you for helping us make KDE software even better for everyone!