1 Apr
2014
1 Apr
'14
02:04
Claudio Freire wrote
Here[0][1] you have an old case involving /var/spool (mailbox delivery).
Googling, I found this one[2] involving /tmp.
Clearly, this is not something new.
==== Those both involve directories with sticky bits that are world writeable. That's a special case. which could be dealt with as not allowing linking to a file owned by someone else in a world writable sticky directory. There is no need to generalize it to all files .
[0] http://www.postfix.org/announcements/20080814.html [1] http://lwn.net/Articles/391474/} [2] http://50.97.85.250-static.reverse.softlayer.com/show/osvdb/96901 -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-factory+owner@opensuse.org