Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The temporary file like /tmp/CCDB is a security issue #5

Closed
mozeq opened this issue Feb 4, 2013 · 1 comment
Closed

The temporary file like /tmp/CCDB is a security issue #5

mozeq opened this issue Feb 4, 2013 · 1 comment

Comments

@mozeq
Copy link
Contributor

mozeq commented Feb 4, 2013

Opened '20090226T12:16:47' by koca as https://fedorahosted.org/abrt/ticket/5

Hi, [[BR]]
The temporary file /tmp/CCDB is a potentially security hole. Malicious users could create e.g symlink and destroy a system file, because daemon is running as a root. [[BR]]
The file /tmp/CCDB would have a random name or saved somewhere where can't write anybody (/var/lock).

@mozeq
Copy link
Contributor Author

mozeq commented Feb 4, 2013

Added '20090226T12:40:28' by 'mnowak'

It's already deprecated. DB is now in /var/cache/crash-catcher (via zprikryl). crash-catcher-0.0.1-5.fc11.x86_64 at least.

@mozeq mozeq closed this as completed Feb 4, 2013
jfilak pushed a commit to jfilak/abrt that referenced this issue Jul 20, 2016
jfilak pushed a commit to jfilak/abrt that referenced this issue Jul 20, 2016
 - btp_rpm_package_sort used qsort the wrong way
 - btp_rpm_package_uniq assumed architecture is always present, which is
   not the case with ABRT reports
 - sort and uniq the package list extracted from ABRT problem dir,
   closes abrt#5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant