Re: Lynx /tmp problem

From: Theo de Raadt (deraadtat_private)
Date: Thu Feb 11 1999 - 11:55:41 PST

  • Next message: Thomas Roessler: "Re: So-called "remote exploit in pine""

    > this bug is lynx specific, so all OS are vulnerables..
    
    OpenBSD ships with an integrated version of lynx.  Our version has
    tweaks to avoid this issue.
    
    We've brought this issue up with the lynx people before.  They do not
    appear to give a damn.
    
    That said, from reading the code I can see why they might not care --
    this problem is going to be a complete nightmare to fix.  Lynx's
    handling of /tmp is wrought with many races, and the code is pasta.
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:33:58 PDT