#10738: insecure temp file in testcc.sh, testcxx.sh
-----------------------+----------------------------------------------------
   Reporter:  vbraun   |       Owner:     
       Type:  defect   |      Status:  new
   Priority:  minor    |   Milestone:     
  Component:  scripts  |    Keywords:     
     Author:           |    Upstream:  N/A
   Reviewer:           |      Merged:     
Work_issues:           |  
-----------------------+----------------------------------------------------
 By preparing a suitable symlink, this lets a local attacker at least
 delete any user file:
 {{{
 [...]
 TESTFILE=/tmp/hkldfz-test-for-c-compiler-6sokljkhsdhfdf.$$.c
 cat >$TESTFILE <<"E*O*F"
 [...]
 }}}
 Is there any reason for not using mktemp?

 Low priority because that is only called during compile time...

-- 
Ticket URL: <http://trac.sagemath.org/sage_trac/ticket/10738>
Sage <http://www.sagemath.org>
Sage: Creating a Viable Open Source Alternative to Magma, Maple, Mathematica, 
and MATLAB

-- 
You received this message because you are subscribed to the Google Groups 
"sage-trac" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/sage-trac?hl=en.

Reply via email to