Bug#373255: [Pkg-aide-maintainers] Bug#373255: Predictable names in tmp are a security risk

2007-04-18 Thread Goswin von Brederlow
Marc Haber [EMAIL PROTECTED] writes: On Tue, Apr 17, 2007 at 03:28:44AM +0200, Goswin von Brederlow wrote: /nonexistant/aide.db or /usr/lib/aid/nonexistant/aide.db. * Change sysconfdir in configure call to /var/lib/aide/please-dont-call-aide-without-parameters to no longer point

Bug#373255: [Pkg-aide-maintainers] Bug#373255: Predictable names in tmp are a security risk

2007-04-17 Thread Goswin von Brederlow
Marc Haber [EMAIL PROTECTED] writes: On Sun, Apr 15, 2007 at 03:21:13PM +0200, Goswin von Brederlow wrote: aide uses a very predictable name in tmp (/tmp/empty/aide.db) with the assumption that it will give an error because the file does not exist. A malicious user can easily create

Bug#373255: [Pkg-aide-maintainers] Bug#373255: Predictable names in tmp are a security risk

2007-04-17 Thread Marc Haber
On Tue, Apr 17, 2007 at 03:28:44AM +0200, Goswin von Brederlow wrote: /nonexistant/aide.db or /usr/lib/aid/nonexistant/aide.db. * Change sysconfdir in configure call to /var/lib/aide/please-dont-call-aide-without-parameters to no longer point to a world writeable location and to give a

Bug#373255: [Pkg-aide-maintainers] Bug#373255: Predictable names in tmp are a security risk

2007-04-15 Thread Marc Haber
On Sun, Apr 15, 2007 at 03:21:13PM +0200, Goswin von Brederlow wrote: aide uses a very predictable name in tmp (/tmp/empty/aide.db) with the assumption that it will give an error because the file does not exist. A malicious user can easily create /tmp/empty and place a dummy db in there and