Bug#359234: libapache2-svn: modules have trapdoor rpath /tmp/svn

Peter Samuelson peter at p12n.org
Mon Mar 27 17:57:13 UTC 2006


[Bill Allombert]
> libapache2-svn modules have a rpath pointing to /tmp:

Ah, quite so.  I ported the nuke-the-rpaths patch to 1.2.3 but
incompletely, intending to finish it when I got a chance (the part with
the apache modules was very confusing to me).  Extra rpaths are usually
quite harmless, but you are right, if a buildd builds things in /tmp,
it can be a security problem.

Note that this does not affect sarge, which (as far as I can recall)
shipped a fully working nuke-the-rpaths patch.

I'll take another look as soon as I get a chance.

Thanks,
Peter
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://lists.alioth.debian.org/pipermail/pkg-subversion-maintainers/attachments/20060327/d9e182fa/attachment.pgp


More information about the pkg-subversion-maintainers mailing list