develooper Front page | perl.perl5.porters | Postings from October 2003

why PERL5LIB is ignored when -T is in effect

Thread Next
From:
Stas Bekman
Date:
October 16, 2003 17:02
Subject:
why PERL5LIB is ignored when -T is in effect
Message ID:
3F8F3171.5060909@stason.org
I know that the perlrun manpage says, that PERL5LIB env var (and a few others) 
are ignored when -t is in effect (and a few other cases). But I can't find any 
explanation to why this needs to be done. The perlsec manpage is not helpful 
here. Me thinking that if a malicious user can change PERL5LIB to something 
undesirable, he can do the same by running:

   perl -I/evil/dir program

I guess I miss something obvious here.

Also I think the fact that PERL5LIB is ignored with -T should be added to the 
perlsec manpage?

Thank you.

__________________________________________________________________
Stas Bekman            JAm_pH ------> Just Another mod_perl Hacker
http://stason.org/     mod_perl Guide ---> http://perl.apache.org
mailto:stas@stason.org http://use.perl.org http://apacheweek.com
http://modperlbook.org http://apache.org   http://ticketmaster.com


Thread Next


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About