[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#79620: dpkg-source must handle file permissions



Wichert Akkerman wrote:
> 
> Unpacking should *never* rely on executing sh code that is part of
> the source package, that makes unpacking a possible security risk.

Agreed. Must be controlled directly by code that interprets special
input.

-- 
Eray (exa) Ozkural
Comp. Sci. Dept., Bilkent University, Ankara
e-mail: erayo@cs.bilkent.edu.tr
www: http://www.cs.bilkent.edu.tr/~erayo



Reply to: