Go to:
Gentoo Home
Documentation
Forums
Lists
Bugs
Planet
Store
Wiki
Get Gentoo!
Gentoo's Bugzilla – Attachment 41098 Details for
Bug 66359
app-crypt/mit-krb5: Insecure tempfile handling
Home
|
New
–
[Ex]
|
Browse
|
Search
|
Privacy Policy
|
[?]
|
Reports
|
Requests
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
[patch]
kerberos5-1.3.4-tempfile.patch
kerberos5-1.3.4-tempfile.patch (text/plain), 1.35 KB, created by
Luke Macken (RETIRED)
on 2004-10-04 15:30:52 UTC
(
hide
)
Description:
kerberos5-1.3.4-tempfile.patch
Filename:
MIME Type:
Creator:
Luke Macken (RETIRED)
Created:
2004-10-04 15:30:52 UTC
Size:
1.35 KB
patch
obsolete
>diff -ur krb5-1.3.4.orig/src/util/send-pr/send-pr.sh krb5-1.3.4/src/util/send-pr/send-pr.sh >--- krb5-1.3.4.orig/src/util/send-pr/send-pr.sh 1997-03-20 01:13:56.000000000 +0100 >+++ krb5-1.3.4/src/util/send-pr/send-pr.sh 2004-09-20 11:28:56.000000000 +0200 >@@ -96,9 +96,9 @@ > fi > fi > >-TEMP=$TMPDIR/p$$ >-BAD=$TMPDIR/pbad$$ >-REF=$TMPDIR/pf$$ >+TEMP=`mktemp -t p.XXXXXX` || exit 1 >+BAD=`mktemp -t pbad.XXXXXX` || exit 1 >+REF=`mktemp -t pf.XXXXXX` || exit 1 > > # find a user name > if [ "$LOGNAME" = "" ]; then >@@ -122,9 +122,10 @@ > else > # Must use temp file due to incompatibilities in quoting behavior > # and to protect shell metacharacters in the expansion of $LOGNAME >- $PASSWD | grep "^$LOGNAME:" | awk -F: '{print $5}' | sed -e 's/,.*//' > $TEMP >- ORIGINATOR="`cat $TEMP`" >- rm -f $TEMP >+ TEMP2=`mktemp -t plogname.XXXXXX` || exit 1 >+ $PASSWD | grep "^$LOGNAME:" | awk -F: '{print $5}' | sed -e 's/,.*//' > $TEMP2 >+ ORIGINATOR="`cat $TEMP2`" >+ rm -f $TEMP2 > fi > > if [ -n "$ORGANIZATION" ]; then >@@ -280,7 +281,7 @@ > # Catch some signals. ($xs kludge needed by Sun /bin/sh) > xs=0 > trap 'rm -f $REF $TEMP; exit $xs' 0 >-trap 'echo "$COMMAND: Aborting ..."; rm -f $REF $TEMP; xs=1; exit' 1 2 3 13 15 >+trap 'echo "$COMMAND: Aborting ..."; rm -f "$REF" "$BAD" "$TEMP"; xs=1; exit' 1 2 3 13 15 > > # If they told us to use a specific file, then do so. > if [ -n "$IN_FILE" ]; then
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 66359
: 41098