Netscape Communicator /tmp Symlink Vulnerability

Predict the name of the temporary file.
ln -sf /elsewhere /tmp/<tmpfilename>

Alternately, a program which watches for the creation of these temporary files, opens them upon their creation, and alters the contents can be written.


 

Privacy Statement
Copyright 2010, SecurityFocus