Comment 4 for bug 607309

Revision history for this message
garo (nikolas) wrote :

There are parts of conky that are linux-only but that are the parts that do things like examine hardware, the rest should work on everything POSIX-compatible.
There is idd still a period between file_exists() and fopen() but the only thing that happens in that time is a stat().
I am by no means a security expert so i could be wrong, but i don't see how a attacker could make that stat() hang long enough to create a symlink