[2726] in bugtraq

home help back first fref pref prev next nref lref last post

Publically writable directories

daemon@ATHENA.MIT.EDU (Thomas Koenig)
Sun Jun 16 12:57:38 1996

Date: 	Sun, 16 Jun 1996 18:30:50 +0200
Reply-To: Bugtraq List <BUGTRAQ@NETSPACE.ORG>
From: Thomas Koenig <ig25@mvmampc66.ciw.uni-karlsruhe.de>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@NETSPACE.ORG>

Is there a safe way of opening a temporary file in a publically writable
directory as a normal user, given a system with symbolic links?
I'm even willing to assume a sticky bit on the directory.

Main problem: How do I disallow a malicious

$ ln -s /tmp/some.file $MYHOME/.somedotfile

at the wrong times, without getting into race conditions?
--
Thomas Koenig, Thomas.Koenig@ciw.uni-karlsruhe.de, ig25@dkauni2.bitnet.
The joy of engineering is to find a straight line on a double
logarithmic diagram.

home help back first fref pref prev next nref lref last post