GNOME Bugzilla – Bug 774498
Can we sandbox tracker-extract with bubblewrap?
Last modified: 2017-07-22 06:06:21 UTC
Inspired by this tracker-related 0day, https://scarybeastsecurity.blogspot.co.il/2016/11/0day-poc-risky-design-decisions-in.html Can we sandbox tracker-extract using bubblewrap[1]? tracker-extract involves parsing a lot of different file types, and since tracker is commonly configured to index quite a lot by default, it's an "obvious" candidate for sandboxing to reduce attack surface. [1] https://github.com/projectatomic/bubblewrap
Duplicate of https://bugzilla.gnome.org/show_bug.cgi?id=764786.
*** This bug has been marked as a duplicate of bug 764786 ***