also sprach Zygo Blaxell <zblax...@feedme.hungrycats.org> [2010.01.21.0848 
+1300]:
> Why does a simple shell script create a vulnerability here?

Because it specifies the filename of a not-yet-created temporary
file and expects results in there.

-- 
 .''`.   martin f. krafft <madd...@d.o>      Related projects:
: :'  :  proud Debian developer               http://debiansystem.info
`. `'`   http://people.debian.org/~madduck    http://vcs-pkg.org
  `-  Debian - when you have better things to do than fixing systems

Attachment: digital_signature_gpg.asc
Description: Digital signature (see http://martin-krafft.net/gpg/)

Reply via email to