Andreas Jaeger
Marcus Meissner
writes: On Fri, Jun 06, 2008 at 11:56:45AM +0200, Stefan Hundhammer wrote:
JFYI - this might affect us, too, at least for debugging or testing.
If there was an announcement anywhere else, I missed it. I read this just by accident on [opensuse]:
LD_PRELOAD does not work for setuid applications - and that's the correct behaviour for quite some time...
Exact behaviour: /* The LD_PRELOAD environment variable gives list of libraries separated by white space or colons that are loaded before the executable's dependencies and prepended to the global scope list. If the binary is running setuid all elements containing a '/' are ignored since it is insecure. */ The comment is from Jan 1997 and last changed Feb 1998, Andreas -- Andreas Jaeger, Director Platform/openSUSE, aj@suse.de SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nürnberg) Maxfeldstr. 5, 90409 Nürnberg, Germany GPG fingerprint = 93A3 365E CE47 B889 DF7F FED1 389A 563C C272 A126