[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages



JC>>> just by looking at the name.
JC>> 
JC>> If program A writes file FILENAME and user1 and user2 can make (write)
JC>> symlinks 'FILENAME' then name of program A is not important.
JC>> 
JC> If that program is in a udeb, then user1 and user2 don't exist, so it's
JC> not a security problem.

Yes, udeb is my mistake :)

--
... mpd is off

. ''`. Dmitry E. Oboukhov
: :’  : unera@debian.org
`. `~’ GPGKey: 1024D / F8E26537 2006-11-21
  `- 1B23 D4F8 8EC0 D902 0555  E438 AB8C 00CF F8E2 6537

Attachment: signature.asc
Description: Digital signature


Reply to: