[Issue 6172] New: rdmd: insecure temporary file creation
d-bugmail at puremagic.com
d-bugmail at puremagic.com
Fri Jun 17 10:22:17 PDT 2011
http://d.puremagic.com/issues/show_bug.cgi?id=6172
Summary: rdmd: insecure temporary file creation
Product: D
Version: unspecified
Platform: All
OS/Version: All
Status: NEW
Severity: critical
Priority: P2
Component: DMD
AssignedTo: nobody at puremagic.com
ReportedBy: edelkind+puremagic at gmail.com
--- Comment #0 from ari edelkind <edelkind+puremagic at gmail.com> 2011-06-17 10:17:34 PDT ---
rdmd will create temporary files in /tmp/.rdmd . A malicious user could
pre-create such a directory and link target files elsewhere.
A more appropriate location for temporary files would be under the user's home
directory (e.g. $HOME/.rdmd). If the user's home directory is unwritable, then
/tmp/.rdmd.[random] may be used.
--
Configure issuemail: http://d.puremagic.com/issues/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
More information about the Digitalmars-d-bugs
mailing list