[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Suggestion to and how to alow different compression for .debs

On Thu, 28 Oct 1999, Wichert Akkerman wrote:

> Let me give another good reason why using a uncompress.sh script is
> something I will never accept: it means that unpacking a package in
> an arbitrary location is no longer a guaranteed safe action, since
> uncompress.sh could do something nasty.

You might want to check out how dpkg actually unpacks the control.tar.gz,
if memory serves me it uses tar without chroot to do it, which means that
control.tar.gz could easially contain /bin/sh or something equally nasty..
So it is hardly a guaranteed safe action right now.

Of course that is fixable, Goswin's idea isn't.


Reply to: