Michael Scherer of Red Hat reports: While trying to upgrade my F19 to F20 using fedup, I noticed that it use a directory in /var/tmp/, with a fixed known name. cachedir = '/var/tmp/fedora-upgrade'
One note, in fedup 0.8.0 (F20) the directory is now /var/tmp/system-upgrade
Filed a bug upstream: https://github.com/wgwoods/fedup/issues/44
Created fedup tracking bugs for this issue: Affects: fedora-all [bug 1067295]
fedup-0.9.0-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
fedup-0.9.0-2.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
fedup-0.9.0-2.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
Fixed in fedup-0.9.0: https://admin.fedoraproject.org/updates/search/CVE-2013-6494