From owner-freebsd-audit Thu Nov 2 20: 9:36 2000 Delivered-To: freebsd-audit@freebsd.org Received: from citusc17.usc.edu (citusc17.usc.edu [128.125.38.177]) by hub.freebsd.org (Postfix) with ESMTP id 0E50637B479; Thu, 2 Nov 2000 20:09:34 -0800 (PST) Received: (from kris@localhost) by citusc17.usc.edu (8.11.1/8.11.1) id eA34AqF26612; Thu, 2 Nov 2000 20:10:52 -0800 (PST) (envelope-from kris) Date: Thu, 2 Nov 2000 20:10:51 -0800 From: Kris Kennaway To: Garance A Drosihn Cc: Mike Heffner , Kris Kennaway , audit@FreeBSD.ORG Subject: Re: sort(1) tempfile patch Message-ID: <20001102201051.A26595@citusc17.usc.edu> References: Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="PNTmBPCT7hxwcZjr" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from drosih@rpi.edu on Thu, Nov 02, 2000 at 10:12:32PM -0500 Sender: owner-freebsd-audit@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG --PNTmBPCT7hxwcZjr Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Thu, Nov 02, 2000 at 10:12:32PM -0500, Garance A Drosihn wrote: > At 6:06 PM -0500 11/2/00, Mike Heffner wrote: > >It was just never applied, I had submitted a PR about it too, > >(bin/16929) and got the reply: > > > >From: Tim Vanderhoek > > To: freebsd-gnats-submit@FreeBSD.org, spock@techfour.net > > Subject: Re: bin/16929: [PATCH] prevent possible race condition > > Date: Tue, 16 May 2000 00:36:58 -0400 (EDT) > > > > > sort can create the following predictable tempfiles: > > > /tmp/sort{pid}{seq} > > > > It appears that the security implications of this have > > already been fixed in rev.1.11 of src/gnu/usr.bin/sort/sort.c. > > > >so nothing was really done about it. >=20 > Does that imply the security issue is already fixed (one > way or another) in rev 1.11, but that we never upgraded > to rev 1.11? I mean, if the security implications were > addressed, then what is it that prompts Kris's update. The security issues were not addressed. Kris --PNTmBPCT7hxwcZjr Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (FreeBSD) Comment: For info see http://www.gnupg.org iEYEARECAAYFAjoCOsoACgkQWry0BWjoQKW5KACg5N45NFzAe5rxKaC4SKGO7/hr j4gAoKYP6gjauB4iDmlcj2Nam5wX33Mr =YSh+ -----END PGP SIGNATURE----- --PNTmBPCT7hxwcZjr-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-audit" in the body of the message