Re: FVWM: fvwmtabs : insecure temp file creation ?

From: Tavis Ormandy <taviso_at_sdf.lonestar.org>
Date: Tue, 23 Mar 2004 20:26:27 +0000

--On Tuesday, March 23, 2004 15:09:48 -0500 xavier
<list.fvwm_at_natch.dyndns.org> wrote:

>
> echo test > /tmp/test
> cd /tmp
> ln -s test .fvwmtabs.state
>
> restart fvwm
>
> /tmp/test is wiped

I also spotted this, it's a configurable setting though...in the gentoo
package I maintain I changed the default to ~/.fvwmtabs.state.

http://www.gentoo.org/cgi-bin/viewcvs.cgi/*checkout*/x11-wm/fvwm/files/fvwm
tabs-insecure-tmp-handling.diff

-- 
-------------------------------------
taviso_at_sdf.lonestar.org | finger me for my gpg key.
-------------------------------------------------------



--
Visit the official FVWM web page at <URL: http://www.fvwm.org/>.
To unsubscribe from the list, send "unsubscribe fvwm" in the body of a
message to majordomo_at_fvwm.org.
To report problems, send mail to fvwm-owner_at_fvwm.org.
Received on Tue Mar 23 2004 - 14:29:10 GMT

This archive was generated by hypermail 2.3.0 : Mon Aug 29 2016 - 19:37:56 BST