On Fri, May 27, 2005 at 03:47:29PM +0200, Paul Bijnens wrote:
> Alexander Jolk wrote:
> >Eric Dantan Rzewnicki wrote:
> >
> >>Did you compile from source or use the debian package from sid?
> >
> >
> >I compiled from source and installed tar into a different location.  Now 
> >if only one could specify which tar to use for amrecover, that would be 
> >most perfect. :-)
> 
> Making that one configurable at run time would be easy, but it
> would also mean that the suid-root program that invokes tar can be
> tricked into executing anything you like, giving root privileges to
> anyone.

Without checking, depending on others :(,
I presume amrecover uses runtar too.

But needs be run as root anyway, no?
Might a special case be possible for amrecover?

-- 
Jon H. LaBadie                  [EMAIL PROTECTED]
 JG Computing
 4455 Province Line Road        (609) 252-0159
 Princeton, NJ  08540-4322      (609) 683-7220 (fax)

Reply via email to