> Doesn't this imply that a full archive rebuild—or at least a targeted audit of packages built while the broken rust-coreutils was active—is necessary to catch all corrupted file permissions across Stonking?
That is a good point. The risk I see here is that a writable file receives executable permissions and becomes exploitable in some way. I'm uncertain about a full archive rebuild, as this only relates to packages using symlinks, so a targeted audit is probably the way to go. In the case of a targeted audit, we could use the release of version 0.0.0~29 of the coreutils-from package, as that's what enabled the cp command. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2165041 Title: cp: Missing setuid flag in su and sudo To manage notifications about this bug go to: https://bugs.launchpad.net/rust-coreutils/+bug/2165041/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
