oss-sec mailing list archives

Re: Fw: Security risk of vim swap files


From: Christian Brabandt <cb () 256bit org>
Date: Sun, 5 Nov 2017 18:17:04 +0100


On Fr, 03 Nov 2017, Jakub Wilk wrote:

In general, what vim does (copying mode bits) in not enough to ensure that
the swapfile is readable only by the users who had access to the original
file. It would have to copy also group ownership and ACLs.

I think patch https://github.com/vim/vim/releases/tag/v8.0.1263 fixes 
the group ownership problem.

Christian
-- 
Advokaten, die Bratenwender der Gesetze, die so lange die Gesetze
wenden und anwenden, bis ein Braten für sie abfällt.
                -- Heinrich Heine


Current thread: