Gentoo Archives: gentoo-dev

From: Martin Schlemmer <azarah@g.o>
To: Jan Krueger <jk@×××××××××××.net>
Cc: Gentoo-Dev <gentoo-dev@g.o>, Thomas de Grenier de Latour <degrenier@×××××××××××.fr>
Subject: Re: [gentoo-dev] suggestion portage ebuild system file modification rights and protection
Date: Sun, 07 Sep 2003 18:17:40
Message-Id: 1062958861.8455.144.camel@nosferatu.lan
In Reply to: Re: [gentoo-dev] suggestion portage ebuild system file modification rights and protection by Jan Krueger
1 On Sun, 2003-09-07 at 22:18, Jan Krueger wrote:
2 > On Sunday 07 September 2003 17:57, Martin Schlemmer wrote:
3 > > and change '${D}/usr/sbin/foo' to '${D}/sbin/init' ?
4 > > (ok, yes, its not going to work as a script if I remember
5 > > correctly .. but a simple c wrapper is quick to code).
6 >
7 > Cool, you just found another security bug in portage!
8 >
9 > go on :)
10 >
11 > So, the required feature thats implied with your detection, would be the
12 > possibility to protect the already installed packages from modification
13 > through installation of another package.
14 >
15
16 And if this was baselayout that was compromised ?
17
18
19 --
20
21 Martin Schlemmer
22 Gentoo Linux Developer, Desktop/System Team Developer
23 Cape Town, South Africa

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] suggestion portage ebuild system file modification rights and protection Jan Krueger <jk@×××××××××××.net>