On 01/08/2013 19:22, Jonathan Wiltshire wrote:
On 2013-08-01 10:40, Paul Verrall wrote:
/usr/local/bin/get_iplayer --pvr 2>>/tmp/get_iplayer.log

There's an unsafe-use-of-temporary-files attack here.

As part of a package, I'd totally agree. And you're right to point it out. In the particular case on what's almost certainly a single-user machine it's probably ok.

Chris


_______________________________________________
get_iplayer mailing list
get_iplayer@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/get_iplayer

Reply via email to