[17578] in bugtraq

home help back first fref pref prev next nref lref last post

Re: StarOffice 5.2 Temporary Dir Vulnerability

daemon@ATHENA.MIT.EDU (Chmouel Boudjnah)
Thu Nov 9 15:35:18 2000

Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Message-Id:  <m3snp1179g.fsf@matrix.mandrakesoft.com>
Date:         Thu, 9 Nov 2000 07:42:51 -0800
Reply-To: Chmouel Boudjnah <chmouel@MANDRAKESOFT.COM>
From: Chmouel Boudjnah <chmouel@MANDRAKESOFT.COM>
X-To:         Kurt Seifried <listuser@seifried.org>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <003f01c049bf$def12260$6900030a@seifried.org>

Kurt Seifried <listuser@seifried.org> writes:

> honor $TMP). Instead of mucking about with /tmp permissions it might be a whole
> lot simpler to chuck a tmp dir into etcskel (and all existing user's dirs) and a
> $TMP definition into the various shell config files (i.e. /etc/profile). I
> believe Mandrake does this now (they told me they'd do it, I haven't actually
> checked the latest release).

if SECURE_TMP is defined in the /etc/sysconfig/system file.

--
MandrakeSoft Inc                     http://www.chmouel.org
                      --Chmouel

home help back first fref pref prev next nref lref last post