On 2013-08-24 18:51:09 -0600, Bob Proulx wrote: > Vincent Lefevre wrote: > > Is it OK that anyone who has a write access in this directory can > > become root on the machine? > > That question is ambiguous. Do you mean that someone who can write to > /foo can use that to become root?
Yes. Say, during an upgrade of the system or package installation, some given file /foo/bar gets executed under root (thanks to ldd). -- Vincent Lefèvre <[email protected]> - Web: <http://www.vinc17.net/> 100% accessible validated (X)HTML - Blog: <http://www.vinc17.net/blog/> Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon) -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

