Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 20 Nov 2000 12:00:08 +0200
From:      Mark Murray <mark@grondar.za>
To:        Kris Kennaway <kris@FreeBSD.ORG>
Cc:        audit@FreeBSD.ORG
Subject:   Re: m4 tempfile fix 
Message-ID:  <200011201000.eAKA09J18620@gratis.grondar.za>
In-Reply-To: <20001119223947.A71937@citusc17.usc.edu> ; from Kris Kennaway <kris@FreeBSD.ORG>  "Sun, 19 Nov 2000 22:39:47 PST."
References:  <20001119223947.A71937@citusc17.usc.edu> 

next in thread | previous in thread | raw e-mail | index | archive | help
> > Don't like it, particularly if the directory is reasonably long-lived.
> >=20
> > All an attacker needs to do is spin-wait for your dir, then cd into it.
> 
> mkdtemp() creates directories mode 0700

No problem, then. Looks good!

M
--
Mark Murray
Join the anti-SPAM movement: http://www.cauce.org


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-audit" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200011201000.eAKA09J18620>