summaryrefslogtreecommitdiff
path: root/BUILD.txt
diff options
context:
space:
mode:
authorJakub Hrozek <jhrozek@redhat.com>2013-01-20 20:27:05 +0100
committerJakub Hrozek <jhrozek@redhat.com>2013-01-23 14:27:58 +0100
commit94cbf1cfb0f88c967f1fb0a4cf23723148868e4a (patch)
tree11f640bd1b848d8e3b295e62bcec69dea188cb69 /BUILD.txt
parent020bf88fd1c5bdac8fc671b37c7118f5378c7047 (diff)
downloadsssd-94cbf1cfb0f88c967f1fb0a4cf23723148868e4a.tar.gz
sssd-94cbf1cfb0f88c967f1fb0a4cf23723148868e4a.tar.bz2
sssd-94cbf1cfb0f88c967f1fb0a4cf23723148868e4a.zip
TOOLS: Use file descriptor to avoid races when creating a home directory
When creating a home directory, the destination tree can be modified in various ways while it is being constructed because directory permissions are set before populating the directory. This can lead to file creation and permission changes outside the target directory tree, using hard links. This security problem was assigned CVE-2013-0219 https://fedorahosted.org/sssd/ticket/1782
Diffstat (limited to 'BUILD.txt')
0 files changed, 0 insertions, 0 deletions