tech-security archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: hardlinks to setuid binaries



> On Mar 25, 2022, at 3:42 PM, Robert Elz <kre%munnari.OZ.AU@localhost> wrote:
> 
> It depends how the update is done.   unlink old, install new,
> will have that effect, but chmod 0 old, unlink old, install
> new does not, nor does cp new old (in all cases, with
> needed chown, chmod, etc, done after the binary update as well).

So, how do pax, tar, and rsync do this?  I expect they are the common means of updating that might lead to this situation, and therefore perhaps likely candidates for reducing the problem (if they do it in an undesired way).

Cheers,
Brook



Home | Main Index | Thread Index | Old Index