Package: gauche
Version: 0.8.6-1
Severity: grave
Justification: allow access to the accounts of users who use the package

Hello Hatta,

gauche-config set a trapdoor rpath:

chrpath usr/bin/gauche-config
usr/bin/gauche-config: 
RPATH=/home/yaegashi/debian/gauche/gauche-0.8.6/build-tree/src

This allows a user with homedir /home/yaegashi to access to the accounts
of users who use gauche-config.

Generally rpath are frowned upon in Debian. You should fix the build
system to not generate them.

Cheers,
-- 
Bill. <[EMAIL PROTECTED]>

Imagine a large red swirl here. 


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to