Re: HEADS UP: Re: FreeBSD Security Advisory FreeBSD-SA-07:01.jai

看板FB_security作者時間19年前 (2007/01/16 05:28), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串8/22 (看更多)
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Pawel Jakub Dawidek wrote: > In other words, it may break existing configurations. Sorry, I meant "pwd -P" and assumed that, according to pwds man page, to be default. >> cd ${jail_root} >> j_root=`pwd` >> cd ${jail_var_log_dir} >> j_var_log=`pwd` >> eval evil_doer=\$\{j_var_log#${j_root}\} >> [ "$evil_doer" = "$j_var_log" ] && exit > > --> Race <-- > >> cp -f ${temp_log} console.log No, since that directory is your cwd, you operate on ./ which wont change by setting soft links along the path. You won't even be able to remove that directory in the first place since the directories vnode is locked. Regards erdgeist -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (Darwin) iD8DBQFFq+7tImmQdUyYEgkRAiJ2AJoCdbM8rPn8F/8atVBRzwGcJOZhHQCeO6Hi ILSZnZ7jgsUhOiZi3M6fkDo= =0IXe -----END PGP SIGNATURE----- _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #15g_7u00 (FB_security)
討論串 (同標題文章)
完整討論串 (本文為第 8 之 22 篇):
文章代碼(AID): #15g_7u00 (FB_security)