The "savetextmode" command (a script typically run by root) writes to /tmp/textregs and /tmp/fontdata without any checks and will happily clobber stuff. Moreover, the programs which actually do the writing (restoretextmode and restorefont) are sometimes setuid root on older linux systems... I have notified RedHat but have not yet heard a response (in 3 days) so I felt it appropriate to post. -Mark
This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:46:53 PDT