Bug#261386: /usr/lib/libkdeinit_dcopserver.so: not using mkstemp, creating temp file unsafely

2004-07-25 Thread Colin Phipps
Package: kdelibs-bin Version: 4:3.2.3-2 Severity: grave File: /usr/lib/libkdeinit_dcopserver.so Tags: security patch Justification: user security hole dcop/dcopserver.cpp creates a temporary file /tmp/dcopXX. This file should be created using mkstemp(3), to avoid /tmp symlink races/attacks.

Bug#261386: /usr/lib/libkdeinit_dcopserver.so: not using mkstemp, creating temp file unsafely

2004-07-25 Thread Matt Zimmerman
Please contact the security team if this is an issue which affects stable. -- - mdz

Bug#261386: /usr/lib/libkdeinit_dcopserver.so: not using mkstemp, creating temp file unsafely

2004-07-25 Thread Alejandro Exojo
El Domingo, 25 de Julio de 2004 19:55, Colin Phipps escribió: diff -pru kdelibs-3.2.3/acinclude.m4 ../kdelibs-3.2.3/acinclude.m4 --- kdelibs-3.2.3/acinclude.m4  2004-07-25 18:08:43.0 +0100 +++ ../kdelibs-3.2.3/acinclude.m4   2004-07-25 18:14:05.0 +0100 FWIW, note that this