BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: gzip TOCTOU file-permissions vulnerability Apr 13 2005 03:40PM
Joey Hess (joeyh debian org)
Martin Pitt wrote:
> Of course the file can be removed by other users after gunzip has
> finished, but that is not a gzip bug, but the result of the really
> dumb idea to have a group/world-writeable directory without the sticky
> bit.

It may be really dumb, but it's pretty common practice too.
Gro...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus