On Thu, 13 Nov 2008 05:12:33 +0100, Andreas J. Koenig <andreas.koenig.7os6VVqR@franz.ak.mind.de> wrote: >> On Wed, 12 Nov 2008 19:13:40 -0800, Michael G Schwern >> <schwern@pobox.com> said: > > > Now that the CPAN shells and archiving modules are handling it at > their end, I > > think the PAUSE filter should be removed. It's not PAUSE's job to be > the code > > police. > > It is 'tar xzf CPANFILE.tar.gz' which is exploitable. No CPAN shell > and archiving module involved. This is why I started the thread proposing to patch EU-MM to change the default tar command line *on Windows*. It will take time to upgrade anyone, yes. But we don't need anyone, we only need those few Windows users who develop their CPAN stuff on Windows. -- CosimoThread Previous | Thread Next