Scrollback buffer saved to /tmp

Bug #949022 reported by Robie Basak
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
vte3 (Ubuntu)
New
Undecided
Unassigned

Bug Description

See report at http://www.climagic.org/bugreports/libvte-scrollback-written-to-disk.html

The scrollback buffer from terminal emulators ends up in /tmp. This is a problem for data displayed in terminals which the user expects never to end up on disk, such as a command line password manager or gpg output.

Further, Ubuntu users using an encrypted home directory with ecryptfs expect data displayed in a terminal to not end up in unencrypted /tmp.

I understand that whether this is really a security vulnerability or acceptable behaviour is debatable.

Workaround: use LUKS for full disk encryption.

Robie Basak (racb)
visibility: private → public
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.