On Wed, Jul 18, 2012 at 9:37 AM, Alon Bar-Lev <alon.bar...@gmail.com> wrote:
> Nobody disables the absolute path use. > This patch permits relative use. > I'm sorry, I misunderstood. So a relative path will now be interpreted as relative to the plugins directory specified a build time, rather than whatever it is relative to now (current working directory?) So please consider my response to have been responding to Heiko's post: On Wed, Jul 18, 2012 at 7:44 AM, Heiko Hund <heiko.h...@sophos.com> wrote: > Specifying a custom full path is probably something we need to ban in the > (near) future, as it imposes an attack vector for privilege escalation by > code > injection when openvpn is not running as another user or has access to > privilege escalation by other means (like the yet to be submitted Windows > interactive service). >