*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Marc Deslauriers 
(mdeslaur):

See report at http://www.climagic.org/bugreports/libvte-scrollback-
written-to-disk.html

The scrollback buffer from terminal emulators ends up in /tmp. This is a
problem for data displayed in terminals which the user expects never to
end up on disk, such as a command line password manager or gpg output.

Further, Ubuntu users using an encrypted home directory with ecryptfs
expect data displayed in a terminal to not end up in unencrypted /tmp.

I understand that whether this is really a security vulnerability or
acceptable behaviour is debatable.

Workaround: use LUKS for full disk encryption.

** Affects: vte3 (Ubuntu)
     Importance: Undecided
         Status: New

-- 
Scrollback buffer saved to /tmp
https://bugs.launchpad.net/bugs/949022
You received this bug notification because you are a member of Ubuntu Bugs, 
which is subscribed to the bug report.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to