Bug 689324 - ps2epsi: insecure temp files
Summary: ps2epsi: insecure temp files
Status: NOTIFIED FIXED
Alias: None
Product: Ghostscript
Classification: Unclassified
Component: General (show other bugs)
Version: master
Hardware: All All
: P4 normal
Assignee: Default assignee
URL: http://www.cups.org/str.php?L1630
Keywords:
Depends on:
Blocks: 689315
  Show dependency tree
 
Reported: 2007-07-04 05:32 UTC by Till Kamppeter
Modified: 2008-12-19 08:31 UTC (History)
0 users

See Also:
Customer:
Word Size: ---


Attachments
mktemp usage in pstoepsi (2.31 KB, patch)
2007-07-04 05:33 UTC, Till Kamppeter
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Till Kamppeter 2007-07-04 05:32:28 UTC
See

http://www.cups.org/str.php?L1630

---------------------------------------------------------------------------------
ps2epsi takes stuff from /tmp where it is could be manipulated.

more verbose description:
http://bugs.gentoo.org/128647
---------------------------------------------------------------------------------

Patch attached.
Comment 1 Till Kamppeter 2007-07-04 05:33:21 UTC
Created attachment 3143 [details]
mktemp usage in pstoepsi
Comment 2 Till Kamppeter 2007-07-04 05:35:07 UTC
The patch uses mktemp only if it exists. On systems without mktemp the old
method is used.
Comment 3 Till Kamppeter 2007-07-05 03:31:42 UTC
Fixed in SVN revision 8103.