> Doesn't this imply that a full archive rebuild—or at least a targeted
audit of packages built while the broken rust-coreutils was active—is
necessary to catch all corrupted file permissions across Stonking?

That is a good point. The risk I see here is that a writable file
receives executable permissions and becomes exploitable in some way. I'm
uncertain about a full archive rebuild, as this only relates to packages
using symlinks, so a targeted audit is probably the way to go.

In the case of a targeted audit, we could use the release of version
0.0.0~29 of the coreutils-from package, as that's what enabled the cp
command.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2165041

Title:
  cp: Missing setuid flag in su and sudo

To manage notifications about this bug go to:
https://bugs.launchpad.net/rust-coreutils/+bug/2165041/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to