1 |
On Sun, 10 Mar 2013 16:46:41 +0100 |
2 |
Michał Górny <mgorny@g.o> wrote: |
3 |
> On Sun, 10 Mar 2013 15:26:29 +0000 |
4 |
> Ciaran McCreesh <ciaran.mccreesh@××××××××××.com> wrote: |
5 |
> > On Sun, 10 Mar 2013 14:48:06 +0100 |
6 |
> > Michał Górny <mgorny@g.o> wrote: |
7 |
> > > Well, unless we're talking about a theoretical package mangler |
8 |
> > > which intentionally uses internal, old version of bash to prove |
9 |
> > > the point. |
10 |
> > |
11 |
> > That's a good idea, maybe we'll do that. Sounds like a good way of |
12 |
> > doing better input validation. Perhaps we could patch our internal |
13 |
> > bash to make it easier to catch certain other errors too. |
14 |
> |
15 |
> Please don't forget to bundle a few rootkits inside, so your users |
16 |
> won't have to wait for security issues to be found in the ye ol' bash |
17 |
> version you'll use. |
18 |
|
19 |
You mean, in the bash that will be being run as root, that is |
20 |
accessible exclusively to packages, all of which are allowed to run |
21 |
things as root, install set*id binaries, etc? |
22 |
|
23 |
-- |
24 |
Ciaran McCreesh |