
oss-sec mailing list archives
Re: Fw: Security risk of vim swap files
From: Adam Shannon <adamkshannon () gmail com>
Date: Tue, 31 Oct 2017 10:41:48 -0400
metasploit has had such a check available for a while now. https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/backup_file.rb On Tue, Oct 31, 2017 at 9:50 AM, Solar Designer <solar () openwall com> wrote:
On Tue, Oct 31, 2017 at 02:35:59PM +0100, Jakub Wilk wrote:There's another problem with vim swapfiles. If you edit a file directly in /tmp, vim will happily read a swapfile that were planted there by somebody else. Local users could exploit this for denial of service (or maybe worse if there are any swapfile parsing bugs...). Is that a bug in vim? Or is it a user error to edit file directly in /tmp?Almost all manual uses of /tmp are user errors, yet we could want to harden programs to make such misuses less risky.In the latter case, we should fix at least vipe(1) and vidir(1) from moreutils; and run-mailcap(1).Alexander
Current thread:
- Fw: Security risk of vim swap files Hanno Böck (Oct 31)
- Re: Fw: Security risk of vim swap files Solar Designer (Oct 31)
- Re: Fw: Security risk of vim swap files Stefan Bühler (Oct 31)
- Re: Fw: Security risk of vim swap files Solar Designer (Oct 31)
- Re: Fw: Security risk of vim swap files Stefan Bühler (Oct 31)
- Re: Fw: Security risk of vim swap files Apostolis Hardalias (Oct 31)
- Re: Fw: Security risk of vim swap files Jakub Wilk (Oct 31)
- Re: Fw: Security risk of vim swap files Solar Designer (Oct 31)
- Re: Fw: Security risk of vim swap files Adam Shannon (Oct 31)
- Re: Fw: Security risk of vim swap files Gordo Lowrey (Oct 31)
- Re: Fw: Security risk of vim swap files Solar Designer (Oct 31)
- Re: Fw: Security risk of vim swap files Jason Cooper (Oct 31)
- Re: Security risk of vim swap files Simon Waters (Surevine) (Oct 31)
- Re: Security risk of vim swap files Matthias Luft (Nov 07)
- Re: Fw: Security risk of vim swap files Tim (Oct 31)
- Re: Fw: Security risk of vim swap files Kurt H Maier (Oct 31)
- Re: Fw: Security risk of vim swap files Tim (Oct 31)
- Re: Fw: Security risk of vim swap files Steffen Nurpmeso (Oct 31)
- Re: Fw: Security risk of vim swap files Leonid Isaev (Nov 01)
- Re: Fw: Security risk of vim swap files Simon McVittie (Nov 01)
- Re: Fw: Security risk of vim swap files Kurt H Maier (Oct 31)
(Thread continues...)
- Re: Fw: Security risk of vim swap files Solar Designer (Oct 31)