Comment 6 for bug 1862348

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

I think shutil.rmtree can be tricked into deleting arbitrary files via a symlink attack. Perhaps the best approach is to simply set the apport lock file as /run/apport.lock?