[Libreoffice] [PATCH] Simplify a function returning the temporary directory name

Tor Lillqvist tlillqvist at novell.com
Wed Jul 13 08:16:33 PDT 2011


Do we really want to have those access() checks there?

I am not evil enough to think of a way to abuse that code (insert maniacal laughter), but in general, isn't that exactly the kind of coding that could be a security vulnerability? (TOCTTOU seems to be the technical term, http://en.wikipedia.org/wiki/Time-of-check-to-time-of-use )

--tml




More information about the LibreOffice mailing list