Re: /bin/pwd

Tomas Hlavaty <[email protected]>
Newsgroups gmane.lisp.clisp.devel
Message-ID <[email protected]>
Hi Sam,

Steingold <[email protected]> writes:
>> * Tomas Hlavaty <[email protected]> [2016-08-30 09:17:33 +0200]:
>> Sam Steingold <[email protected]> writes:
>>> running external programs without a full path is a security risk.
>>
>> What is the reasoning behind this assertion?
>
> * if clisp executes "pwd" and
> * you have, say, "~/bin" in your $PATH before "/bin" and
> * a malicious actor plants an executable named "pwd" into "~/bin", then
>   you will run that executable as yourself.

thanks for your reply.

Tomas

------------------------------------------------------------------------------
_______________________________________________
clisp-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/clisp-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.