Summary: | net-im/ntame-998020954 insecure temporary file creation | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Romang <zataz> |
Component: | Auditing | Assignee: | Gentoo Security <security> |
Status: | RESOLVED INVALID | ||
Severity: | normal | ||
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Package list: | Runtime testing required: | --- |
Description
Romang
2005-05-31 00:14:31 UTC
that code is #ifdef DEBUG'ed out, the ebuild never defines that macro so a user would have to add that to their CFLAGS in order to ever reach the code. Nevertheless, perhaps the O_APPEND should be replaced with O_EXCL or DEBUG_PATH set to "ntaim-debug.log" instead, I would suggest reassigning to net-im herd. conferred with security team, marking INVALID. |