* Jonas Smedegaard:

> git-repair uses /tmp/tmprepo.0/.git/ which is clearly static, and I
> believe therefore (on non-hardened systems) insecure.

I think it does mkdir and if it fails, it tries again with
/tmp/tmprepo.1, /tmp/tmrepo.2, and so on.  I'm not sure you can abuse
this and fool git-repair into using a pre-existing directory with mode
777.  At least not with non-historic NFS.

Florian

Reply via email to