Package: libpam-tmpdir Version: 0.05-2 Severity: normal Tags: patch The directory libpam-tmpdir used to create the users' temporary directories in can be set within /etc/security/tmpdir.conf. This is not mentioned anywhere.
*** /tmp/tmpdir.patch diff -Nur pam-tmpdir-0.05/README pam-tmpdir-0.05.orig/README --- pam-tmpdir-0.05/README 2005-11-13 19:26:24.077460248 +0100 +++ pam-tmpdir-0.05.orig/README 2005-11-13 19:21:32.513784664 +0100 @@ -20,11 +20,3 @@ login if an error occurs while setting up the safe tmpdir, this could allow for a DoS attack if a malicious user gets the chance to create /tmp/user before pam_tmpdir does. - -The directory in which the users' temporory directories are created -can be set using an entry in /etc/security/tmpdir.conf: - -tmpdir=/path/to/tmpdir - -pam_tmpdir will fail to create a safe tmpdir if this directory is -group or world writable. -- System Information: Debian Release: testing/unstable APT prefers testing APT policy: (500, 'testing') Architecture: i386 (i686) Shell: /bin/sh linked to /bin/bash Kernel: Linux 2.6.12.1 Locale: LANG=C, [EMAIL PROTECTED] (charmap=ISO-8859-15) Versions of packages libpam-tmpdir depends on: ii libc6 2.3.5-6 GNU C Library: Shared libraries an libpam-tmpdir recommends no packages. -- no debconf information -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]