bug-gnu-utils
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: temp file creation bug in diffutils 2.7


From: Alan Cox
Subject: Re: temp file creation bug in diffutils 2.7
Date: Thu, 28 Dec 2000 02:34:49 +0000 (GMT)

> > That seems strange. On old SYS5 unix boxes you will recompile a dangerously
> > insecure binary rather than refuse to build
> 
> Ancient hosts without proper O_EXCL support can be used safely if all
> users trust each other.  I don't see the point of refusing to support
> such environments.  The patch is safe on all modern hosts.

The reason to at least warn people is that the operators of such an environment
are not likely to be aware that the FSF is shipping dangerous insecure code
unless it errors.

./configure --insecure

yes

but blindly making someones box insecure - bad bad move. It might even be
your credit card data that is stolen thanks to that decision




reply via email to

[Prev in Thread] Current Thread [Next in Thread]