Bugtraq mailing list archives

Re: BoS: [BUG] Vulnerability in TIN


From: rosebud () cyclone Stanford EDU (Larry Schwimmer)
Date: Tue, 3 Sep 1996 03:22:30 -0700


You (Shyne-Song Chuang) write:
I am not sure if this is a known vulnerability, but the newsreader
tin also has a problem with mode 666 temp files.

        I consider it well known, but that could just be me.
        In any event, add

        -DDONT_LOG_USER

to your Makefile, and it won't compile in this code.  Security hole
aside, it is also potential an invasion of user privacy.

                        yours,
                                Larry Schwimmer
                                schwim () cyclone stanford edu
                                Distributed Computing Operations



Current thread: