gnu-arch-users
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Gnu-arch-users] patch: clean up some cacherev mess


From: Derek Zhou
Subject: RE: [Gnu-arch-users] patch: clean up some cacherev mess
Date: Wed, 23 Nov 2005 13:07:22 -0800

Alfred M. Szmidt wrote:
> 
>    Probably not going to happen. I read somewhere that if users are
>    allowed to reap /tmp anytime at will, a malicious user can exploit
>    some race condition in tmp file creation to do privilege
>    escalation.
> 
> Could you dig up the article?  I can't see any reasons why it wouldn't
> be utterly trivial to make such a program totally abuse safe.
>
I am not going to pretend I know anything about computer security.
However, the first rule that I obey is: "Do not make anything suid root
unless absolutly necessary!"
Derek 




reply via email to

[Prev in Thread] Current Thread [Next in Thread]