oss-sec mailing list archives

Re: Running Java across a privilege boundry


From: Martin Carpenter <mcarpenter () free fr>
Date: Thu, 18 Dec 2014 14:53:36 +0100

On Thu, 2014-12-18 at 10:45 +0100, Jakub Wilk wrote:

https://bugs.debian.org/754278

Could this have been caught in package QA with an automated check on
R(UN)PATH? 

(If that exists, how did it get missed? If not, could it be added?
Where? https://wiki.debian.org/qa.debian.org).


Alternatively: is there ever a good argument for truly relative (ie not
"relative to $ORIGIN") R(UN)PATH? What would break if runtime linkers
did not accept relative R(UN)PATHs?



Current thread: