Posted by Simon McVittie on Sep 26 Was this library advertised as being safe for use in setuid, setgid or otherwise privileged processes? Looking at its description in my package manager ("provides developers of file-sharing networks, file managers, and WWW-indexing bots with a universal library to obtain meta-data about files") I don't immediately see why it would be appropriate for a setuid program to use this. I think it's going to scale incredibly...

Read the full article at oss-security →