http://d.puremagic.com/issues/show_bug.cgi?id=6172

           Summary: rdmd: insecure temporary file creation
           Product: D
           Version: unspecified
          Platform: All
        OS/Version: All
            Status: NEW
          Severity: critical
          Priority: P2
         Component: DMD
        AssignedTo: nob...@puremagic.com
        ReportedBy: edelkind+purema...@gmail.com


--- Comment #0 from ari edelkind <edelkind+purema...@gmail.com> 2011-06-17 
10:17:34 PDT ---
rdmd will create temporary files in /tmp/.rdmd .  A malicious user could
pre-create such a directory and link target files elsewhere.

A more appropriate location for temporary files would be under the user's home
directory (e.g. $HOME/.rdmd).  If the user's home directory is unwritable, then
/tmp/.rdmd.[random] may be used.

-- 
Configure issuemail: http://d.puremagic.com/issues/userprefs.cgi?tab=email
------- You are receiving this mail because: -------

Reply via email to