BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: gzip TOCTOU file-permissions vulnerability Apr 13 2005 02:49PM
Derek Martin (code pizzashack org)
On Tue, Apr 12, 2005 at 01:47:01PM +0200, Martin Pitt wrote:
[SNIP]
> > Vulnerability
> > ==============
> >
> > If a malicious local user has write access to a directory in which a
> > target user is using gzip to extract or compress a file to then a
> > TOCTOU bug can be exploited to change the p...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus