Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: gzip TOCTOU file-permissions vulnerability Apr 14 2005 12:29AM
psz maths usyd edu au
Joey Hess <joeyh (at) debian (dot) org [email concealed]> wrote:

>> ... really dumb idea to have a group/world-writeable directory
>> without the sticky bit.
>
> It may be really dumb, but it's pretty common practice too. ...
> Just a few examples within the Debian project ...

Kindly add the Debian example:

psz@pisa:/usr/lo...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus