Trond Eivind Glomsrød writes:
> When you install (not configure for, just install) into a separate tree
> (for easier packaging), it's a hole which can be exploited - some packages
> will rpath into /var/tmp/<foo>, for instance. Hackers can then put their
> own library there.
"Some packages"... ;-)
> One big offender here is perl's automatic module
> creation script which will change the rpaths from what you told it when
> you built it to what you do when you install it.
This should be fixed now, although the perl module will actually not obey
the --disable-rpath switch. Can't have everything, I guess...
--
Peter Eisentraut peter_e@gmx.net