[Pkg-haskell-maintainers] Bug#787227: Acknowledgement (broken on armel due to broken RUNPATH: /usr/lib/ghc/bin/ghc: error while loading shared libraries: libHShaskeline-0.7.1.2-ghc7.8.4.so: cannot open shared object file: No such file or directory)

Joey Hess id at joeyh.name
Sat May 30 02:05:06 UTC 2015


Note that this bug is likely a security hole; /usr/bin/ghc loading .so
files relative to the CWD could be exploted.

When ghc's postinst runs ghc-pkg, it seems that dpkg does something that
prevents those relative paths being used (possibly just a chdir, didn't
check). So, it's at least not trivially exploitable by getting root to
install ghc when root is in /tmp.

-- 
see shy jo
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 811 bytes
Desc: Digital signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-haskell-maintainers/attachments/20150529/dff67984/attachment.sig>


More information about the Pkg-haskell-maintainers mailing list