Bugtraq mailing list archives

Re: Lynx /tmp problem


From: deraadt () CVS OPENBSD ORG (Theo de Raadt)
Date: Thu, 11 Feb 1999 12:55:41 -0700


this bug is lynx specific, so all OS are vulnerables..

OpenBSD ships with an integrated version of lynx.  Our version has
tweaks to avoid this issue.

We've brought this issue up with the lynx people before.  They do not
appear to give a damn.

That said, from reading the code I can see why they might not care --
this problem is going to be a complete nightmare to fix.  Lynx's
handling of /tmp is wrought with many races, and the code is pasta.



Current thread: