[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <86d6cny01v.fsf@blue.stonehenge.com>
From: merlyn at stonehenge.com (Randal L. Schwartz)
Subject: Re: Gaim festival plugin exploit
>>>>> "Dale" == Dale Harris <rodmur@...be.org> writes:
Dale> So let me guess open FEST "|..." uses popen(), right?
No, it doesn't. It uses its own code, which looks at the string
to see if there are shell constructs, and if not, avoids the
shell by parsing whitespace and args on its own.
--
Randal L. Schwartz - Stonehenge Consulting Services, Inc. - +1 503 777 0095
<merlyn@...nehenge.com> <URL:http://www.stonehenge.com/merlyn/>
Perl/Unix/security consulting, Technical writing, Comedy, etc. etc.
See PerlTraining.Stonehenge.com for onsite and open-enrollment Perl training!
Powered by blists - more mailing lists