Checkbox should use /var/cache instead of /tmp for files run as root

Bug #517861 reported by Marc Tardif
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Checkbox
Fix Released
Critical
Marc Tardif

Bug Description

If some suites download files which may eventually run as root, this should be done under /var/cache instead of /tmp. Otherwise, someone can potentially create a security vulnerability under /tmp which would be called blindly as root. Also, anything long standing should potentially be stored under /var/cache.

Marc Tardif (cr3)
Changed in checkbox:
assignee: nobody → Marc Tardif (cr3)
milestone: none → 0.9-featurefreeze
Marc Tardif (cr3)
Changed in checkbox:
importance: Undecided → Critical
status: New → Fix Committed
Marc Tardif (cr3)
Changed in checkbox:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.