[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages



On Mon, Aug 11, 2008 at 18:59:22 +0400, Dmitry E. Oboukhov wrote:

> MdI> just by looking at the name.
> 
> If program A writes file FILENAME and user1 and user2 can make (write)
> symlinks 'FILENAME' then name of program A is not important. 
> 
If that program is in a udeb, then user1 and user2 don't exist, so it's
not a security problem.

Cheers,
Julien


Reply to: