Trond Eivind Glomsrød writes:
> When you install (not configure for, just install) into a separate tree
> (for easier packaging), it's a hole which can be exploited - some packages
> will rpath into /var/tmp/<foo>, for  instance. Hackers can then put their
> own library there.
"Some packages"... ;-)
> One big offender here is perl's automatic module
> creation script which will change the rpaths from what you told it when
> you built it to what you do when you install it.
This should be fixed now, although the perl module will actually not obey
the --disable-rpath switch.  Can't have everything, I guess...
-- 
Peter Eisentraut   peter_e@gmx.net