time for some OpenBSD-style auditing?

2000-12-28 Thread Joe Buck
Notice that security holes fall into classes? One category of hole should be easy to eliminate from Debian by instituting a code auditing requirement. I'm referring to insecure creation of temporary files, allowing for symlink attacks. Now that we all know what this hole looks like, it should be

time for some OpenBSD-style auditing?

2000-12-28 Thread Joe Buck
Notice that security holes fall into classes? One category of hole should be easy to eliminate from Debian by instituting a code auditing requirement. I'm referring to insecure creation of temporary files, allowing for symlink attacks. Now that we all know what this hole looks like, it should b