[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: LYNX-DEV Re: ...vulnerability in Lynx...
From: |
Alan Cox |
Subject: |
Re: LYNX-DEV Re: ...vulnerability in Lynx... |
Date: |
Mon, 12 May 1997 09:35:16 +0100 (BST) |
> If a system is set up with a "sticky" temp directory, and lynx creates a
> subdirectory there with resonable permissions, can it use the current method
> of creating temp files without becoming a tool for hackers to compromise
> security?
If the subdirectory is created mode 0700 then yes except on older HP's,
and that is well known anyway
> In this case, despite all the other issues, making lynx use a safe subdir
> on a system with a safe tempfile is a good fix. Further modification to
> Lynx to improve saftey on such systems, or on systems without a safe temp
> dir are seperate issues that don't have to be dealt with.
Well it doesnt matter if the same directory is /tmp/lynx-$USER$PID or
~user/.lynx as a configuration you get both out of the fix
;
; To UNSUBSCRIBE: Send a mail message to address@hidden
; with "unsubscribe lynx-dev" (without the
; quotation marks) on a line by itself.
;
- Re: LYNX-DEV Re: ...vulnerability in Lynx..., (continued)
- Re: LYNX-DEV Re: ...vulnerability in Lynx..., Brian Tillman, x8425, 1997/05/09
- Re: LYNX-DEV Re: ...vulnerability in Lynx..., Scott McGee (Personal), 1997/05/09
- Re: LYNX-DEV Re: ...vulnerability in Lynx..., Scott McGee (Personal), 1997/05/09
- Re: LYNX-DEV Re: ...vulnerability in Lynx..., Scott McGee (Personal), 1997/05/09
- Re: LYNX-DEV Re: ...vulnerability in Lynx..., Scott McGee (Personal), 1997/05/09
- Re: LYNX-DEV Re: ...vulnerability in Lynx..., Jonathan Sergent, 1997/05/09
- LYNX-DEV Re: ...vulnerability in Lynx - code, Klaus Weide, 1997/05/09
- Re: LYNX-DEV Re: ...vulnerability in Lynx - code, Jonathan Sergent, 1997/05/10
- LYNX-DEV Re: mkstemp source, Larry W. Virden, x2487, 1997/05/10
- Re: LYNX-DEV Re: mkstemp source, T.E.Dickey, 1997/05/10
- Re: LYNX-DEV Re: mkstemp source, Larry W. Virden, x2487, 1997/05/10
- Re: LYNX-DEV Re: mkstemp source, Jonathan Sergent, 1997/05/10
- Re: LYNX-DEV Re: mkstemp source, Larry W. Virden, x2487, 1997/05/10