[Yum-devel] writing out the cache and yum-utils

Hans-Peter Jansen hpj at urpla.net
Sat Jun 18 12:22:53 UTC 2005


Am Samstag, 18. Juni 2005 13:50 schrieb seth vidal:
>
> you'd still need to make it a randomly determined dir (mkstemp)
> otherwise we'd be opening up for an exploit.

Forgive my sillyness, but if this dir is 0700 and owned by the user, how 
can this be exploited by another user? 

Pete



More information about the Yum-devel mailing list