[pass] FreeBSD Port: sysutils/password-store

Jason A. Donenfeld Jason at zx2c4.com
Wed Apr 16 19:57:21 CEST 2014


On Wed, Apr 16, 2014 at 5:23 PM, milki <milki at rescomp.berkeley.edu> wrote:
> On 13:10 Wed 16 Apr     , Jason A. Donenfeld wrote:
>> Setuiding mdconfig will probably result in some kind of local priv
>> escalation bug. I don't want to do that.
>
> Right, so I recommend removing the freebsd.sh from platform to prevent
> any temp file leaks with the false assumption that the temp dir is
> secure.

Done.
http://git.zx2c4.com/password-store/commit/?id=eb87d5dee176f8d7057d05d24302040ab1b56768


More information about the Password-Store mailing list