Bugtraq mailing list archives

Re: another /tmp race: `perl -e' opens temp file not safely


From: deraadt () CVS OPENBSD ORG (Theo de Raadt)
Date: Sat, 7 Mar 1998 23:44:18 -0700


All this complexity of trivial things (just open a temp file) is one
of the reasons I think the whole idea of /tmp is a fundamental
misdesign and eventually one should be able to chmod it to 755 (while
programs should use per-user TMPDIRs).

Which, as I've said before, works REALLY well for setuid programs.

Imagine:

TMPDIR=/

Or how would you solve that problem?



Current thread: