Dendrobatus Azureus<p>The Deepin frightmare </p><p>Excerpt from linked site<br>>><br>After reviewing the main D-Bus service, we could not help ourselves but call it a security nightmare. The service methods were not only unauthenticated and thus accessible to all users in the system, but the D-Bus configuration file also allowed anybody to own the D-Bus service path on the system bus, which could lead to impersonation of the daemon. Among other issues, the D-Bus service allowed anybody in the system to create arbitrary new UNIX groups, add arbitrary users to arbitrary groups, set arbitrary users’ Samba passwords or overwrite almost any file on the system by invoking mkfs on them as root, leading to data loss and denial-of-service. The daemon did contain some Polkit authentication code, but it was all found in unused code paths; to top it all off, this code used the deprecated UnixProcess Polkit subject in an unsafe way, which would make it vulnerable to race conditions allowing authentication bypass, if it had been used.<br><<</p><p>¿WTF?</p><p><a href="https://security.opensuse.org/2025/05/07/deepin-desktop-removal.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.opensuse.org/2025/05/</span><span class="invisible">07/deepin-desktop-removal.html</span></a></p><p><a href="https://mastodon.bsd.cafe/tags/openSUSE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openSUSE</span></a> <a href="https://mastodon.bsd.cafe/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> <a href="https://mastodon.bsd.cafe/tags/POSIX" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>POSIX</span></a> <a href="https://mastodon.bsd.cafe/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://mastodon.bsd.cafe/tags/programming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>programming</span></a> <br><a href="https://mastodon.bsd.cafe/tags/Deepin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Deepin</span></a> <a href="https://mastodon.bsd.cafe/tags/WTF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WTF</span></a> <a href="https://mastodon.bsd.cafe/tags/frightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>frightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/Infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Infosec</span></a> <a href="https://mastodon.bsd.cafe/tags/nightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/elmStreet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>elmStreet</span></a></p>