develooper Front page | perl.qa | Postings from November 2008

Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists

Thread Previous | Thread Next
From:
Cosimo Streppone
Date:
November 13, 2008 07:35
Subject:
Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists
Message ID:
op.ukkdlck88c52c6@id-c0805.oslo.opera.com
On Thu, 13 Nov 2008 05:12:33 +0100, Andreas J. Koenig  
<andreas.koenig.7os6VVqR@franz.ak.mind.de> wrote:

>> On Wed, 12 Nov 2008 19:13:40 -0800, Michael G Schwern  
>> <schwern@pobox.com> said:
>
> > Now that the CPAN shells and archiving modules are handling it at  
> their end, I
> > think the PAUSE filter should be removed.  It's not PAUSE's job to be  
> the code
> > police.
>
> It is 'tar xzf CPANFILE.tar.gz' which is exploitable. No CPAN shell
> and archiving module involved.

This is why I started the thread proposing to patch EU-MM
to change the default tar command line *on Windows*.

It will take time to upgrade anyone, yes.

But we don't need anyone, we only need those few Windows
users who develop their CPAN stuff on Windows.

-- 
Cosimo

Thread Previous | Thread Next


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About