Re: RemoveSETUID feature (Was: Summary/Minutes from today's FESCo meeting (2010-10-26) NEW TIME!)

2010-12-21 Thread Dick Tayter
2010/12/21 Miloslav Trmač: > If an attacker were controlling a process running with uid 0 and no > capabilities at all, and /bin/sh were 0555, nothing prevents the > attacker from chmod()ing /bin/sh to 0755 and overwriting it. This makes > any attempts to change the file permissions rather pointl

Re: Upstream bugs vs. Fedora bugs: KDE people do it wrong

2010-03-31 Thread Dick Tayter
On 31 March 2010 08:28, Jaroslav Reznik wrote: > So please - start reporting again - I hope I explained what does "UPSTREAM" > resolution mean. I can't promise you, we (Fedora, KDE SIG, KDE upstream or > whoever) fix the bug but... > I had a bug some time ago in Okular that I reported and was to