Do we really want to have those access() checks there?

I am not evil enough to think of a way to abuse that code (insert maniacal 
laughter), but in general, isn't that exactly the kind of coding that could be 
a security vulnerability? (TOCTTOU seems to be the technical term, 
http://en.wikipedia.org/wiki/Time-of-check-to-time-of-use )

--tml


_______________________________________________
LibreOffice mailing list
LibreOffice@lists.freedesktop.org
http://lists.freedesktop.org/mailman/listinfo/libreoffice

Reply via email to