This is the mail archive of the
automake@gnu.org
mailing list for the automake project.
Re: libtool /tmp security
- To: Akim Demaille <akim at epita dot fr>, Alexandre Oliva <oliva at lsd dot ic dot unicamp dot br>
- Subject: Re: libtool /tmp security
- From: Earnie Boyd <earnie_boyd at yahoo dot com>
- Date: Wed, 15 Mar 2000 06:08:26 -0800 (PST)
- Cc: "Gary V. Vaughan" <gary at oranda dot demon dot co dot uk>, "Joseph S. Myers" <jsm28 at cam dot ac dot uk>, bug-libtool at gnu dot org, autoconf at gnu dot org, automake at gnu dot org
- Reply-To: earnie_boyd at yahoo dot com
--- Akim Demaille <akim@epita.fr> wrote:
-8<-
>
> As for mkdir -m, it seems to me that
>
> (umask 700 && mkdir /tmp/foo)
>
> is just fine.
>
-8<-
Why use /tmp at all? Since autoconf is for portibility you can't really assume
that /tmp exists. Why not simply create a temporary directory in the current
working directory? IMO this would handle any security issues as well as any
race issues.
Earnie.
__________________________________________________
Do You Yahoo!?
Talk to your friends online with Yahoo! Messenger.
http://im.yahoo.com