Re: Policy Weekly Issue #4/6: Secure maintainer scripts

1997-12-08 Thread Guy Maor
Joey Hess <[EMAIL PROTECTED]> writes: > Christian Schwarz wrote: > I don't think this is good enough. The point isn't really to do this, it's > to create files in /tmp in a secure manner. Uh, yes: > > The Debian base distribution provides the `tempfile' utility for > > use by scripts f

Re: Policy Weekly Issue #4/6: Secure maintainer scripts

1997-10-23 Thread Joey Hess
Christian Schwarz wrote: > The following policy change has been proposed. It will become official > unless someone objects now: > > Any scripts which create files in world-writable directories (i.e. > in /tmp) have to use a mechanism which will fail if a file with > the same name al

Policy Weekly Issue #4/6: Secure maintainer scripts

1997-10-23 Thread Christian Schwarz
Topic 6: Secure maintainer scripts STATE: APPROVAL The following policy change has been proposed. It will become official unless someone objects now: Any scripts which create files in world-writable directories (i.e. in /tmp) have to use a mechanism which will fail if a file with