Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20171106071158.GC9438@256bit.org>
Date: Mon, 6 Nov 2017 08:11:58 +0100
From: Christian Brabandt <cb@...bit.org>
To: oss-security@...ts.openwall.com
Subject: Re: Fw: Security risk of vim swap files


On So, 05 Nov 2017, Solar Designer wrote:

> Yes, let's also force 0600 for "undo and backup files", please.

Backup files and undo files are not created by default, only when Vim is 
configured to do so. Also the undofile does not leak any information, 
because as soon as the original file has been slightly altered, the undo 
information is discarded.

Christian
-- 
Den ungerechtesten Frieden finde ich immer noch besser als den
gerechtesten Krieg.
		-- Marcus Tullius Cicero (106-43 v.Chr.)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.