Still can if its random. The attacker can be the one who exec's the
vulnerable app. The attacker can use dnotify
> things it's not supposed to. Like forcing suid apps to create
> a file in the startup-scripts dir. or something.
Just use namespaces and give every login their own /tmp
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/