[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: problems with latest x version in incoming



Joey Hess wrote:
> Adam P. Harris wrote:
> > Hmmm.  I wonder if putting setuid in the .deb itself (rather than
> > chmoding in the postinst) defeats the purpose of suidregister?
> > Maybe I've been wrong?
> 
> Well, it certianly does not defeat the porpose of suidregister. Suidregister
> will happily override it.

However, suidregister will override it at configuration time, while the
suid bit is set at unpack time.  This leaves a window which may be
arbitrarily long.

Richard Braakman


Reply to: