Constantin Musca
<[email protected]> writes:
> + process_tmpdir = os.path.join('/tmp', str(os.getpid()))
> + if os.path.exists(process_tmpdir):
> + shutil.rmtree(process_tmpdir)
> + os.makedirs(process_tmpdir)
ooohhhh... this violates trivial rules regarding secure generation of
tempfiles. Better use 'mkdtemp()' from the 'tempfile' module.
Enrico
_______________________________________________
Openembedded-core mailing list
[email protected]
http://lists.linuxtogo.org/cgi-bin/mailman/listinfo/openembedded-core