Bugtraq mailing list archives
Re: [hacksware]Pine temporary file hijacking vulnerability
From: Thomas Corriher <corriher () bellsouth net>
Date: Mon, 11 Dec 2000 17:00:49 -0500
So many of these problems would just disappear if the system's default profile had something like "$TMPDIR=$HOME" or "$TMPDIR=$HOME/tmp". Pine is not really the problem. Poorly configured systems are the problem. Linux distributors: are you paying attention? Why should all users be given full access to any directory; especially if most programs are designed to use that directory by default? It is time that we wake up certain corporations and software distribution companies. This sloppiness should not be tolerated. This type of problem appears again, and again, and again; yet these problems could be fixed with a one-liner. Oh the insanity! I am not even an expert on security matters, but I do know enough about the basics to realize that many default configurations are incredibly stupid. -- From the desk of Thomas Corriher Sent via Red Hat Linux Phone: +1-704-921-2470
Current thread:
- [hacksware]Pine temporary file hijacking vulnerability JW Oh (Dec 12)
- Re: [hacksware]Pine temporary file hijacking vulnerability Thomas Corriher (Dec 13)
- Re: where user temp files should go, env var names Peter W (Dec 14)
- Re: where user temp files should go, env var names Andrzej Chabierski (Dec 16)
- Re: where user temp files should go, env var names Valdis Kletnieks (Dec 18)
- Re: where user temp files should go, env var names Aaron Drew (Dec 18)
- Re: where user temp files should go, env var names Mike A. Harris (Dec 19)
- Re: where user temp files should go, env var names Nick Phillips (Dec 21)
- Re: where user temp files should go, env var names Peter J . Holzer (Dec 21)
- Re: where user temp files should go, env var names Doug Wyatt (Dec 21)
- Message not available
- Re: where user temp files should go, env var names Jay R. Ashworth (Dec 21)
- Re: where user temp files should go, env var names Peter W (Dec 14)
- Re: [hacksware]Pine temporary file hijacking vulnerability Thomas Corriher (Dec 13)
