Amanda-Users

Re: tar versions (was Re: "implausibly old time stamp")

2005-05-27 10:55:17
Subject: Re: tar versions (was Re: "implausibly old time stamp")
From: Jon LaBadie <jon AT jgcomp DOT com>
To: amanda-users AT amanda DOT org
Date: Fri, 27 May 2005 10:34:22 -0400
On Fri, May 27, 2005 at 03:47:29PM +0200, Paul Bijnens wrote:
> Alexander Jolk wrote:
> >Eric Dantan Rzewnicki wrote:
> >
> >>Did you compile from source or use the debian package from sid?
> >
> >
> >I compiled from source and installed tar into a different location.  Now 
> >if only one could specify which tar to use for amrecover, that would be 
> >most perfect. :-)
> 
> Making that one configurable at run time would be easy, but it
> would also mean that the suid-root program that invokes tar can be
> tricked into executing anything you like, giving root privileges to
> anyone.

Without checking, depending on others :(,
I presume amrecover uses runtar too.

But needs be run as root anyway, no?
Might a special case be possible for amrecover?

-- 
Jon H. LaBadie                  jon AT jgcomp DOT com
 JG Computing
 4455 Province Line Road        (609) 252-0159
 Princeton, NJ  08540-4322      (609) 683-7220 (fax)