What is up2date repackaging?

James Olin Oden joden at malachi.lee.k12.nc.us
Tue Oct 14 11:04:23 UTC 2003


On Tue, 14 Oct 2003, Julio Sanchez wrote:

> On Mon, 13 Oct 2003 20:20:30 -0400, James Olin Oden wrote:
> 
> > There not really broken, there just not the same thing (-;
> > Really, there perceived brokeness stems from the fact that 
> > they pick up the files of the rpm as they are on the system 
> > at that time.
> 
> Do I see a security problem?  The few I have seen seem to be
> world-readable.  Might some sensitive files end there?
> 
Had not thought of that.  Its easy enough to tighten the perms on the
directory that the repackaged packages go into, but then one can still get 
to the files (and the names are pretty regular, so...).   If Jeff Johnson
did not see this message I will make sure he does so we can get his 
thoughts on this.  It should be pretty easy to fix, just want to make 
sure the implications are understood.

Cheers...james
> Or is it just by accident that mine ended up as world-readable?
> 
> Julio
> 
> 
> 
> --
> fedora-test-list mailing list
> fedora-test-list at redhat.com
> http://www.redhat.com/mailman/listinfo/fedora-test-list
> 





More information about the fedora-test-list mailing list