From: | CARNIL [...] cpan.org |
Subject: | srs: /tmp/srsd socket schould not be in /tmp |
Hi,
We have the following bug reported to the Debian package of Mail-SRS
(https://bugs.debian.org/898383):
Show quoted text
> /tmp is a bad place for the srsd socket. Unfortunately that pathname is
> hardcoded (/usr/bin/srsd, line 15). It is probably not an exploitable
> insecure tempfile creation, nonetheless it should not be there.
Regards,
Salvatore