Re: FVWM: fvwmtabs : insecure temp file creation ?

2004-03-24 Thread Scott Smedley
 I also spotted this, it's a configurable setting though...in the gentoo
 package I maintain I changed the default to ~/.fvwmtabs.state.

A good idea. I'll make this the default from now on:

*FvwmTabs: stateFile $[HOME]/.fvwmtabs.state

Thanks,

SCoTT. :)
--
Visit the official FVWM web page at URL: http://www.fvwm.org/.
To unsubscribe from the list, send unsubscribe fvwm in the body of a
message to [EMAIL PROTECTED]
To report problems, send mail to [EMAIL PROTECTED]


FVWM: fvwmtabs : insecure temp file creation ?

2004-03-23 Thread xavier

echo test  /tmp/test
cd /tmp
ln -s test .fvwmtabs.state

restart fvwm

/tmp/test is wiped




-- 
xavier
--
Visit the official FVWM web page at URL: http://www.fvwm.org/.
To unsubscribe from the list, send unsubscribe fvwm in the body of a
message to [EMAIL PROTECTED]
To report problems, send mail to [EMAIL PROTECTED]


Re: FVWM: fvwmtabs : insecure temp file creation ?

2004-03-23 Thread Tavis Ormandy


--On Tuesday, March 23, 2004 15:09:48 -0500 xavier
[EMAIL PROTECTED] wrote:

 
 echo test  /tmp/test
 cd /tmp
 ln -s test .fvwmtabs.state
 
 restart fvwm
 
 /tmp/test is wiped

I also spotted this, it's a configurable setting though...in the gentoo
package I maintain I changed the default to ~/.fvwmtabs.state.

http://www.gentoo.org/cgi-bin/viewcvs.cgi/*checkout*/x11-wm/fvwm/files/fvwm
tabs-insecure-tmp-handling.diff

-- 
-
[EMAIL PROTECTED] | finger me for my gpg key.
---


pgpSF7o8pZH1T.pgp
Description: PGP signature