I have just started to learn the GNUstep's development environment and I
have in my very first program stumbled across a serious security problem
in the way Objective-C handles IO. Obviously, Objective-C does not
honour Unix file permissions. You can reproduce this problem on
Unix/Linux systems by setting {{ chmod 000 /some/dir/your.data }}, and
then run the example program in the GNUstep documentation page (Base
Programming Manual/The Objective-C Language) under "2.8.5 Loading and
Saving Strings" by setting the path to {{ /some/dir/your.data }}.

Torli
_______________________________________________
Discuss-gnustep mailing list
[email protected]
http://lists.gnu.org/mailman/listinfo/discuss-gnustep

Reply via email to