Re: Bug#19797: libc6-dev: use of /tmp/*$$ in an insecure fashion
> > That is correct, 'tempfile' is Debian specific, and we also ship a similar
> > utility from OpenBSD called 'mktemp', I have no idea if other systems also
> > have 'mktemp' utilities.
> The glibcbug script in glibc 2.1 already uses mktemp.
Perhaps the `tempfile' name was a bad choice. Should appropriate
symlinks to `mktemp' be considered (or a companion `mktemp' helper if
the invocation syntax differs) for closer OpenBSD compatibility?
Since the `tempfile' helper was introduced for hamm, a name change to
`mktemp' might be still feasable, but that would disrupt the hamm freeze.
--
To UNSUBSCRIBE, email to debian-policy-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Reply to: