Comment 37 for bug 885027

Revision history for this message
navs (navs) wrote :

Warning to all:
I'd be wary running this 70-calibreassaultmount.sh on multi user systems. The temporary file used to drop a payload is created in an insecure manner and can be exploited to execute code under the context of the user.
I would like ubuntu for not including this obviously exploitable test case in the face of an arrogant security researcher.