[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#19797: libc6-dev: use of /tmp/*$$ in an insecure fashion




> > That is correct, 'tempfile' is Debian specific, and we also ship a similar
> > utility from OpenBSD called 'mktemp', I have no idea if other systems also
> > have 'mktemp' utilities.
> The glibcbug script in glibc 2.1 already uses mktemp.

Perhaps the `tempfile' name was a bad choice.  Should appropriate
symlinks to `mktemp' be considered (or a companion `mktemp' helper if
the invocation syntax differs) for closer OpenBSD compatibility?
Since the `tempfile' helper was introduced for hamm, a name change to
`mktemp' might be still feasable, but that would disrupt the hamm freeze.


--  
To UNSUBSCRIBE, email to debian-policy-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org


Reply to: