Updater reduces security of installed versions

Bug #1443652 reported by James Ross
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Open Rails
Fix Released
Medium
James Ross

Bug Description

When updating an installed version of Open Rails, the installer creates the new files in a temporary directory in the root of the same drive. This directory, by default, is less secure than Program Files, which is where it moves the files. Moving files keeps their security descriptors, so although the directory Program Files\Open Rails is still protected, the individual files within are not.

This should be easy to fix by reverting to using the installation directory for the temporary files.

James Ross (twpol)
Changed in or:
importance: Undecided → Medium
Revision history for this message
James Ross (twpol) wrote :

Not quite as simple as expected but fixed in X3006.

Changed in or:
status: Triaged → In Progress
status: In Progress → Fix Committed
James Ross (twpol)
Changed in or:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.