develooper Front page | perl.perl5.porters | Postings from October 2003

Re: [perl #24291] Taint checking against the wrong environment

Thread Previous | Thread Next
From:
Nicholas Clark
Date:
October 26, 2003 15:40
Subject:
Re: [perl #24291] Taint checking against the wrong environment
Message ID:
20031026234016.GR52109@plum.flirble.org
On Sun, Oct 26, 2003 at 11:31:42PM +0000, Ton Hospel wrote:
> In article <20031027002524.7b444942.rgarciasuarez@_ree._r>,
> 	Rafael Garcia-Suarez <rgarciasuarez@free.fr> writes:
> > Maybe do nothing and let people shoot in their feet.
> >
> > Maybe just forbid aliasing *ENV at all. (with the collateral damage
> > on $ENV etc.) (or couldn't this chained alias thing be solved
> > by looking at the GvEGV ?)
> 
> Crashing, dieing, compile erors  etc. are all solutions (though
> certainly not my preferred solutions), but doing nothing isn't
> acceptable since it's a potential security hole.

SEGVs better than continuing? I can't agree.

Nicholas Clark


Thread Previous | Thread Next


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About