Re: [Full-disclosure] Vim: Insecure Temporary File Creation During Build: Arbitrary Code Execution

2008-07-26 Thread Jan Minář
On Fri, Jul 25, 2008 at 4:57 PM, Steven M. Christey <[EMAIL PROTECTED]> wrote: > > On Fri, 25 Jul 2008, [UTF-8] Jan MináÅ^Y wrote: > >> > The commands do not have to be written there between (1) and (2), they >> > can be in the file long before the ./configure was started -- just >> > because the s

Re: [Full-disclosure] Vim: Insecure Temporary File Creation During Build: Arbitrary Code Execution

2008-07-25 Thread Robert Buchholz
On Friday 25 July 2008, Jan Minář wrote: > 2008/7/25 Robert Buchholz <[EMAIL PROTECTED]>: > > On Friday 18 July 2008, Jan Minář wrote: > > ... > > > >> 3. Vulnerability > >> > >> During the build process, a temporary file with a predictable name > >> is created in the ``/tmp'' directory. This code

Re: [Full-disclosure] Vim: Insecure Temporary File Creation During Build: Arbitrary Code Execution

2008-07-25 Thread Steven M. Christey
On Fri, 25 Jul 2008, [UTF-8] Jan Miná�^Y wrote: > > The commands do not have to be written there between (1) and (2), they > > can be in the file long before the ./configure was started -- just > > because the script does care whether it can write to the file at all. > > So unlike stated in the a

Re: [Full-disclosure] Vim: Insecure Temporary File Creation During Build: Arbitrary Code Execution

2008-07-25 Thread Robert Buchholz
On Friday 18 July 2008, Jan Minář wrote: ... > 3. Vulnerability > > During the build process, a temporary file with a predictable name is > created in the ``/tmp'' directory. This code is run when Vim is > being build with Python support: > > src/configure.in: > > 677 dnl -- we ne

Re: [Full-disclosure] Vim: Insecure Temporary File Creation During Build: Arbitrary Code Execution

2008-07-25 Thread Jan Minář
2008/7/25 Robert Buchholz <[EMAIL PROTECTED]>: > On Friday 18 July 2008, Jan Minář wrote: > ... >> 3. Vulnerability >> >> During the build process, a temporary file with a predictable name is >> created in the ``/tmp'' directory. This code is run when Vim is >> being build with Python support: >>