This bug was fixed in the package checkinstall - 1.7.0-1
---------------
checkinstall (1.7.0-1) unstable; urgency=medium
* New upstream release, now maintained at
https://github.com/ssgelm/checkinstall
- A mode set on a symlink no longer reaches the file it points at.
fchmodat() dropped AT_SYMLINK_NOFOLLOW, so a binary installed 755 came
out of the package writable by anyone, and a link extracted before its
target aborted the install (LP: #1861281)
- Keep names that contain consecutive spaces. The file list was carried
as space separated words, so such a name came back with one space and
the file was dropped from the package (LP: #1953239)
- Build on alpha, where glibc is libc.so.6.1
* Drop 38 patches, all now in the upstream release
* Update copyright file with correct licenses and copyrights
* Build the manpages from upstream's SGML rather than the copies
in debian/
* Bump debhelper compat to 14
-- Stephen Gelman <[email protected]> Fri, 07 Aug 2026 14:29:01 -0500
** Changed in: checkinstall (Ubuntu)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1861281
Title:
checkinstall adds local root exploits to any package with a symlink in
it
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/checkinstall/+bug/1861281/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs