Re: ssh-keygen: error if file is directory

[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

 



> On Jan 9, 2025, at 10:31, Bob Proulx <bob@xxxxxxxxxx> wrote:
> 
> [...] In cases where
> something is checked and then later used there is a gap of time when
> the thing that was checked might be moved out of the way and replaced
> with a different thing before it is used.  That's a classic race
> condition attack. [...]

Thanks for calling that out, Bob.

This class of defect is sometimes referred to as [TOCTOU][*]. (The "Preventing TOCTOU" section talks about why the OpenSSH code is structured as it is: "EAFP").

[*]: https://en.m.wikipedia.org/wiki/Time-of-check_to_time-of-use

-- 
jim knoble

_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@xxxxxxxxxxx
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev




[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux