Re: buglet in ext2 sticky bit?

Jan Vroonhof (vroonhof@math.ethz.ch)
25 Oct 1999 18:37:19 +0200


Fuzzy Fox <fox@foxtaur.com> writes:

> > AFAIK a file writable for everyone should be deletable when +t on the
> > parent dir.
>
> I disagree. A malicious user could remove the "aap" file, and then
> recreate it with permissions that disallow writes by others.

Can you give a concrete example? If he is malicious, why does he have
write access to the file in the first place? If the existence of the
file is that important, why is it in a directory with write access?

Jan

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/