Previously Jason Gunthorpe wrote:
> You might want to check out how dpkg actually unpacks the control.tar.gz,
> if memory serves me it uses tar without chroot to do it, which means that
> control.tar.gz could easially contain /bin/sh or something equally nasty..

It uses an internal tar-implementation actually. You will need to use
a symlinked directory, but it will indeed work. I think I know what I'll
be working on tonight..


 / Generally uninteresting signature - ignore at your convenience  \
| [EMAIL PROTECTED]           |
| 1024D/2FA3BC2D 576E 100B 518D 2F16 36B0  2805 3CB8 9250 2FA3 BC2D |

Attachment: pgpda2w6H9hhV.pgp
Description: PGP signature

Reply via email to