Re: Adobe Acrobat creates world writable ~/AdobeFnt.lst files

From: wim@djo.wtm.tudelft.nl
Date: 08/22/01


Message-ID: <20010822185446.6738.qmail@djo.wtm.tudelft.nl>
From: wim@djo.wtm.tudelft.nl
Subject: Re: Adobe Acrobat creates world writable ~/AdobeFnt.lst files
To: Darren.Moffat@eng.sun.com
Date: Wed, 22 Aug 2001 20:54:46 +0200 (MEST)


> >Adobe Acrobat creates world writable ~/AdobeFnt.lst files
...
> Another possible workaround would be to create a shared object that
> replaced the open/chmod calls that change the permissions on the file,
> this could then be LD_PRELOAD'd so that acroread doesn't do the wrong thing.
>
> Using truss on Solaris we can easily see that acroread actually makes
> an explicit call to set the permissions to 0666.

And what if that call fails?
chattr +i will do miracles, I imagine.

Regards, Wim.



Relevant Pages

  • Re: Acrobat reader 5.05 temp file insecurity
    ... The directory does not have world-writeable permissions. ... > Acroread creates or overwrites the file /tmp/AdobeFnt06.lst.UID, ... > and wait for victim to use acroread; then we can write his .bashrc. ... > respect the setting of TMPDIR in the environment: ...
    (Bugtraq)
  • Re: Acrobat reader 5.05 temp file insecurity
    ... ('binary' encoding is not supported, ... >Acroread creates or overwrites the file ... >changes its permissions to wide open; ... >and wait for victim to use acroread; ...
    (Bugtraq)
  • Acrobat reader 5.05 temp file insecurity
    ... and wait for victim to use acroread; then we can write his .bashrc. ... respect the setting of TMPDIR in the environment: ... Does not Adobe know that? ... Thanks to a user of my system, for noticing the wide-open permissions on ...
    (comp.security.unix)
  • Acrobat reader 5.05 temp file insecurity
    ... and wait for victim to use acroread; then we can write his .bashrc. ... respect the setting of TMPDIR in the environment: ... Does not Adobe know that? ... Thanks to a user of my system, for noticing the wide-open permissions on ...
    (comp.security.unix)
  • Acrobat reader 5.05 temp file insecurity
    ... and wait for victim to use acroread; then we can write his .bashrc. ... respect the setting of TMPDIR in the environment: ... Does not Adobe know that? ... Thanks to a user of my system, for noticing the wide-open permissions on ...
    (Bugtraq)

Loading