On Mon, 03 Mar 2014, Jakub Wilk wrote:
> perltidy creates temporary files with default permissions,
> potentially disclosing information that wouldn't be otherwise
> accessible to local users. Temporary files should be always created
> with mode 0600.

Thanks for the report. This whole bit should probably be ripped out and
replaced by File::Temp::tempfile too, as tmpnam isn't even remotely
secure, either.

-- 
Don Armstrong                      http://www.donarmstrong.com

Creativity can be a social contribution, but only in so far
as society is free to use the results. 
 -- Richard M Stallman _GNU Manifesto_


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to