Bug#3140: etc/init.d/boot has rm -f bugs
You (Marek Michalkiewicz) wrote:
> Chris Fearnley:
> > Why the hell is this done at boot-up (sorry, but I had a crash and lost
> > a /tmp file that was an editing session, hoo boy). At least keep things
> > in /tmp for 3 days!!!
>
> I agree that things in /tmp should be kept for at least 3 days - but...
Okay. I have fixed this. As I said in a previous message, there should
be a seperate config file to set policy like this, that can be parsed
by the boot scripts on startup.
> > Moreover this is a security bug as indicated in the recent discussion
> > on find and rm.
>
> At the time /etc/init.d/boot is run, there are probably no users logged
> in and trying to exploit the race condition. So, I don't think this is
> a security bug...
Exactly. Ofcourse if I'm wrong about this please tell me.
Mike.
--
Miquel van | Cistron Internet Services -- Alphen aan den Rijn.
Smoorenburg, | mailto:info@cistron.nl http://www.cistron.nl/
miquels@het.net | Tel: +31-172-419445 (Voice) 430979 (Fax) 442580 (Data)
Reply to: