From owner-freebsd-security Fri Feb 22 10:53:22 2002 Delivered-To: freebsd-security@freebsd.org Received: from post.mail.nl.demon.net (post-11.mail.nl.demon.net [194.159.73.21]) by hub.freebsd.org (Postfix) with ESMTP id 4DFDE37B404 for ; Fri, 22 Feb 2002 10:53:19 -0800 (PST) Received: from [212.238.194.207] (helo=mailhost.raggedclown.net) by post.mail.nl.demon.net with esmtp (Exim 3.33 #1) id 16eKoo-000PEJ-00 for freebsd-security@freebsd.org; Fri, 22 Feb 2002 18:53:18 +0000 Received: from angel.raggedclown.net (angel.raggedclown.intra [192.168.1.7]) by mailhost.raggedclown.net (Ragged Clown Mail Gateway [buffy]) with ESMTP id 593F113040 for ; Fri, 22 Feb 2002 19:53:17 +0100 (CET) Received: by angel.raggedclown.net (Ragged Clown Host [angel], from userid 1005) id 2D918225C1; Fri, 22 Feb 2002 19:53:17 +0100 (CET) Date: Fri, 22 Feb 2002 19:53:17 +0100 From: Cliff Sarginson To: "'freebsd-security@freebsd.org'" Subject: Re: Third /tmp location ? Message-ID: <20020222185317.GA6328@raggedclown.net> References: Mime-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: User-Agent: Mutt/1.3.27i Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On Fri, Feb 22, 2002 at 12:18:02PM +0100, Milo? Pape?ík wrote: > Hi all, > > I was very surprised when I found on freshly installed 4.5RELEASE third > world writable directory /usr/tmp. > > Is there any real reason for this "likely to be forgotten" location ? > Why is on out of box installation ? Isn't the /tmp and /var/tmp enough pain > ? > The only light I can throw on this is that in one of my regular forays into getting KDE to work properly I discovered it made a complaint about /usr/tmp not being writable. I throw this into the maelstrom of speculation. (and no I don't have /tmp symlinked to /usr/tmp). -- Regards Cliff Sarginson -- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message