from the dont-forget-the-static-binaries dept.
"Patches have been released for the fts libc functions.
It is possible to trick a program traversing a directory structure to go outside of that directory structure.
the patch is at
. The patch tells you to apply the patch and recompile libc but it neglects to tell you about staticly compiled binaries. (hint /bin and /sbin and a few binaries in /usr/bin /usr/sbin and /usr/libexec)"
the patch notice already, but Bill's remarks about static binaries bear mention. Also, thanks go out to Joshua Stein for the 2.9 topic icon.