Re: problems with latest x version in incoming
Joey Hess wrote:
> Adam P. Harris wrote:
> > Hmmm. I wonder if putting setuid in the .deb itself (rather than
> > chmoding in the postinst) defeats the purpose of suidregister?
> > Maybe I've been wrong?
>
> Well, it certianly does not defeat the porpose of suidregister. Suidregister
> will happily override it.
However, suidregister will override it at configuration time, while the
suid bit is set at unpack time. This leaves a window which may be
arbitrarily long.
Richard Braakman
Reply to: