/tmp issue with savetextmode

From: Mark A. Spencer (mspencerat_private)
Date: Mon Mar 23 1998 - 10:39:06 PST

  • Next message: martin Dolphin: "Re: RAS 'save password' problems..."

    The "savetextmode" command (a script typically run by root) writes to
    /tmp/textregs and /tmp/fontdata without any checks and will happily
    clobber stuff.
    
    Moreover, the programs which actually do the writing (restoretextmode and
    restorefont) are sometimes setuid root on older linux systems...
    
    I have notified RedHat but have not yet heard a response (in 3 days) so I
    felt it appropriate to post.
    
                                            -Mark
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:46:53 PDT