insecure tmp file creation (slack)

From: neonhaze (bmacdonaldat_private)
Date: Mon Apr 06 1998 - 04:29:44 PDT

  • Next message: ReverendTW: "Bug in M$ Solitare"

    Linux Slackware
    
    I don't know which of these are already known so please bare with me.
    
    When the following programs are run they create /tmp files that do not
    check for links and will happily overwrite any file when the program is
    running as root. So link one of them to your favorite root owned file you
    would like to destroy (or edit in pkgtool's case) and wait for root to run
    the affected program.
    
    -Affected Program-    -File created in /tmp-       -Created File Perms-
    liloconfig-color            reply                   -rw-r--r--
    pkgtool                     reply                   -rw-rw-rw-
    makebootdisk                return                  -rw-r--r--
    netconfig                   tmpmsg                  -rw-r--r--
    
    found by neonhaze <neonhazeat_private>
                      <bmacdonaldat_private>
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:48:01 PDT