[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#77257: FWD: Joe's Own Editor File Link Vulnerability

Colin Phipps <cph@netcraft.com> wrote:
> A fix, but it breaks the intended behaviour ("a" for append IIRC). Putting 
> DEADJOE in $HOME might be a nicer solution?

No please, temporary files have no place in a user's home directory, because
unlike /tmp it won't be deleted until the user intervenes in the event of a

Do the right thing and use tmpfile(3).
Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ )
Email:  Herbert Xu ~{PmV>HI~} <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Reply to: