Bugtraq mailing list archives

Publically writable directories


From: ig25 () mvmampc66 ciw uni-karlsruhe de (Thomas Koenig)
Date: Sun, 16 Jun 1996 18:30:50 +0200


Is there a safe way of opening a temporary file in a publically writable
directory as a normal user, given a system with symbolic links?
I'm even willing to assume a sticky bit on the directory.

Main problem: How do I disallow a malicious

$ ln -s /tmp/some.file $MYHOME/.somedotfile

at the wrong times, without getting into race conditions?
--
Thomas Koenig, Thomas.Koenig () ciw uni-karlsruhe de, ig25@dkauni2.bitnet.
The joy of engineering is to find a straight line on a double
logarithmic diagram.



Current thread: