Sanitize environment variables as early as possible.
For example, on Mandriva, if SECURE_TMP is enabled (in /etc/security/shell), then TMP/TMPDIR are set to $HOME/tmp but $HOME is only accessible by the owner and its group, but not slap user, then the extends-cache temporary directory will not be accessible after dropping the privileges.
Showing
Please register or sign in to comment