On Wed, Jul 18, 2012 at 9:37 AM, Alon Bar-Lev <alon.bar...@gmail.com> wrote:

> Nobody disables the absolute path use.
> This patch permits relative use.
>

I'm sorry, I misunderstood. So a relative path will now be interpreted as
relative to the plugins directory specified a build time, rather than
whatever it is relative to now (current working directory?)

So please consider my response to have been responding to Heiko's post:

On Wed, Jul 18, 2012 at 7:44 AM, Heiko Hund <heiko.h...@sophos.com> wrote:

> Specifying a custom full path is probably something we need to ban in the
> (near) future, as it imposes an attack vector for privilege escalation by
> code
> injection when openvpn is not running as another user or has access to
> privilege escalation by other means (like the yet to be submitted Windows
> interactive service).
>

Reply via email to