[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: /var/games/package must be 770



>> 
>> It is a security problem. A user can overwrite the highscore files to
>> exploit a
>> buffer overflow in the game and wait for another user to play. A user can
>> also
>> store large file in it to escape quota on /home dir, or to break the /var
>> partition, or to hide setuid binaries?, etc...
> 
> Stretching a little, but fair enough.
> 

Not a stretch at all.  This was kind of thing was very very common in our CS
department.



Reply to: