Re: RFH: Insecure directory creation?

2006-12-24 Thread Loïc Minier
On Sat, Dec 23, 2006, Javier Fernández-Sanguino Peña wrote: First, /var/tmp/mach itself is currently shipped in the package (.deb) itself; it serves as the base directory to copy over RPM files. Copy over RPM files from where? mach can be used to 1) create chroots and 2) build RPM

Re: RFH: Insecure directory creation?

2006-12-23 Thread Loïc Minier
On Fri, Dec 22, 2006, Javier Fernández-Sanguino Peña wrote: I don't know how mach operates precisely, would you care to elaborate how and when does it use /var/tmp/mach/? What files are created there? What control does the user have on the content or naming of those files? First,

Re: RFH: Insecure directory creation?

2006-12-23 Thread Javier Fernández-Sanguino Peña
On Sat, Dec 23, 2006 at 11:20:12AM +0100, Loïc Minier wrote: On Fri, Dec 22, 2006, Javier Fernández-Sanguino Peña wrote: I don't know how mach operates precisely, would you care to elaborate how and when does it use /var/tmp/mach/? What files are created there? What control does the user

Re: RFH: Insecure directory creation?

2006-12-22 Thread Javier Fernández-Sanguino Peña
On Fri, Dec 22, 2006 at 01:51:20PM +0100, Loïc Minier wrote: Would someone be so kind to either correct me or to help me word why this is a bad idea? This is a bad idea because, if mach creates (on installation) /var/tmp/mach/something, and a rogue user creates (before installation)