Hey Dave, are you suggesting that no such exploits exist in Red Hat's
rpm system? In order for that to be true, rpm would have to be making
sure that each and every directory along any path that it writes is
not writable except by priviledged users. I just checked, it doesn't.
We can sit here all day and make a big deal out of this, I think it's a
waste of time. I'm not an advocate of insecure software and I'm happy
to close any holes that people think need closing, but you're just
wasting time. This isn't an issue. If you really, really cared, there
is nothing to prevent you from downloading the BK image, unpacking it on
a throwaway machine, back it back up again in a shar file or whatever,
and then installing it.
At some point, people get to take responsibility for their own choices.
----- Larry McVoy lm at bitmover.com http://www.bitmover.com/lm - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to firstname.lastname@example.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/