httpd-docs mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Eric Covener" <cove...@gmail.com>
Subject Re: help for translation
Date Thu, 02 Oct 2008 21:31:15 GMT
>>>> "Omitting this option should not be considered a security restriction,
>>>> since symlink testing is subject to race conditions that make it
>>>> circumventable.

> "Omitting this option should not be considered a security enhancement,
> because the time while testing symlinks can be subject to race conditions
> and so the security measure taken omitting this option can be circumvented.

The end of this new sentence confuses me more then simply "race
condition" in the original, but I do agree that "make it
circumventable" could use some work.

"Omitting this option should not be considered a security measure,
because there remains a race condition in the span of time between
checking that a path component is not a symlink and then subsequently
using that path component."

(a little redundant to explain "race condition")

-- 
Eric Covener
covener@gmail.com

---------------------------------------------------------------------
To unsubscribe, e-mail: docs-unsubscribe@httpd.apache.org
For additional commands, e-mail: docs-help@httpd.apache.org


Mime
View raw message