Re: [Openvpn-devel] [PATCH] clean up / rewrite sample-plugins/defer/simple.c

2021-01-21 Thread Arne Schwabe
Am 21.01.21 um 18:25 schrieb Gert Doering: > If we ship something that we consider a form of documentation > "this is how to write an OpenVPN plugin" it should meet our standards > for secure and modern code. This plugin did neither. > > - get rid of system() calls, especially those that

[Openvpn-devel] [PATCH] clean up / rewrite sample-plugins/defer/simple.c

2021-01-21 Thread Gert Doering
If we ship something that we consider a form of documentation "this is how to write an OpenVPN plugin" it should meet our standards for secure and modern code. This plugin did neither. - get rid of system() calls, especially those that enabled a remote-root exploit if this code was used