develooper Front page | perl.qa | Postings from September 2008

Re: [RFC] Dealing with World-writable Files in the Archive of CPANDistributions

Thread Previous | Thread Next
From:
Michael Peters
Date:
September 22, 2008 09:26
Subject:
Re: [RFC] Dealing with World-writable Files in the Archive of CPANDistributions
Message ID:
48D7C6C8.1000300@plusthree.com
Ovid wrote:

> Correct me if I've misunderstood something, but if you have a malicious user on your box, I would assume that them trying to attack a CPAN install process is the least of your worries. 

You're right. If they are a malicious user then they will find a way to screw you. I'm just saying 
that since we know about this path, let's eliminate it, or at least make it public and known.

>  This is a CPANTS issue.

I agree.

-- 
Michael Peters
Plus Three, LP


Thread Previous | Thread Next


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About