[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)



On Mon, Apr 19, 2004 at 06:40:35PM +0200, Jan Minar wrote:

> Could You tell us what _exactly_ happened?  (DWN cover-story ;-))  Are
> there no testsuites/scripts to ensure basic sanity of the packages being
> built packages?  Or what _exactly_ was the mistake (I'm personally
> interested in the security weaknesses of the build process).

Some masochistic part of me really wants to know how you can twist a broken
package build, missing a bunch of files, into a "security weakness".

-- 
 - mdz



Reply to: