Bug#330350: [Pkg-shadow-devel] Bug#330350: passwd: Potential symlink attack problem in remove-shell?

Christian Perrier bubulle at debian.org
Wed Sep 28 04:47:50 UTC 2005


> This doesn't look that bad to me.
> Here, the temporary file is in /etc/. If somebody can create a symlink in
> /etc/, she can probably also change /etc/shadow.


Yes, right.

However, don't you think we'd better use a non-predictable temporary
file name ?






More information about the Pkg-shadow-devel mailing list