14 msgProFTPD still vulnerable (Sarge)
1 msgWannt new Proshe or BMW?
16 msgMass update deployment strategy
1 msgDolly wrote:
3 msgtexinfo update?
1 msgBilly wrote:
3 msgUnidentified subject!

'... creates temporary files in an insecure man...
\ s. keeling (21 Nov 2006)
. \ Sam Morris (21 Nov 2006)
. \ Javier Fernández-Sanguino Peña (23 Nov 2006)

1 msgwatch this stck go crazy c
1 msgPrimo sesso nella vtia qui
1 msgmore All admins access
1 msgIs succumb go postwar
1 msgUPDATE: Remote Root In Nvidia xserver Driver
2 msgBypassing allowed_users with PAM in sshd?
1 msgËîãèñòèêà çàêóïîê
1 msgGive us a call when you get a chance
9 msghelp needed
2 msgRegister
1 msgº£¡ËÍâ¡ËÒÑ1400ÍòÈËÉùÃ÷Íˡˡ൳¡ËÍÅ£¬Ìì¡ËÃðÖС˹...
6 msgbind9 security problem?
Subject:Re: '... creates temporary files in an insecure manner.' Tutorial?
Group:Debian-security
From:Javier Fernández-Sanguino Peña
Date:23 Nov 2006


 

On Mon, Nov 20, 2006 at 09:33:14PM -0700, s. keeling wrote:
>
> I'm wondering whether there might be some "secure temporary file
> checklist" which should be part of the
> indoctrination<ESC><BackSpace>initiation phase for DDs?

Well, I tried to write some information for DDs in the "Securing Debian
Manual": Chapter 9 - Developer's Best Practices for OS Security
http://www.debian.org/doc/manuals/securing-debian-howto/ch9.en.html
and this year at Debconf 6:
- slides: http://people.debian.org/~jfs/debconf6/weeding_security_bugs.pdf
and (slides + examples) at:
http://meetings-archive.debian.net/pub/debian-meetings/2006/debconf6/slides/Weed ing_out_security_bugs-Javier_Fernandez_Sanguino/
- video: available at
http://meetings-archive.debian.net/pub/debian-meetings/2006/debconf6/

HTH

Javier



© 2004-2008 readlist.com