Re: [security]: kernel ioctl()'s [3]

Bryn Paul Arnold Jones (bpaj@gytha.demon.co.uk)
Sun, 4 Jul 1999 14:50:24 +0100 (GMT)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Fri, 2 Jul 1999, Jamie Lokier wrote:

> Theodore Y. Ts'o wrote:
> > (Yes, I realize there are a few differences, such as it
> > prevents unlinking the file, and you can't do that without changing the
> > permissions on the containing directory, which you might not own.)
>
> Security alert... if I hard link to some elses file and they set the
> user-immutable bit (and deleted their last link) I can't clean out my
> own directory?
>

Can't be done, the file is immutable so they can't unlink it until they
remove the user-immutable bit. To end up with the file immutable again
they have to set the immutable bit in your directory.

> -- Jamie
>
Bryn
- --
Or words to that effect ...
PGP pubkeys from http://www.gytha.demon.co.uk/pubkey.asc.

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 5.0i for non-commercial use
Comment: Silly comment here ...
Charset: noconv

iQA/AwUBN39mpd94IUtvfSqaEQKIfgCfUNyIYYUqmBCIPcXoPB2yHVl0uvkAoP4o
77W0IJZ8y7TezcY7XI048IFY
=VjAp
-----END PGP SIGNATURE-----

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/