mkinitrd: possibly insecure temp directory creation
Bug #12182 reported by
Danilo Piazzalunga
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
initrd-tools (Ubuntu) |
Fix Released
|
Medium
|
Jeff Bailey |
Bug Description
mkinitrd creates a temporary directory (its workdir) in a possibly insecure way.
Making it use mktemp is a trivial one-line change.
To post a comment you must log in.
Created an attachment (id=1113)
Use mktemp instead of $$ to create the working directory