|
Message-ID: <50C9BBA7.5020307@debian.org> Date: Thu, 13 Dec 2012 11:27:35 +0000 From: Simon McVittie <smcv@...ian.org> To: oss-security@...ts.openwall.com Subject: Re: Geany IDE not escaping filenames during compilation / build - a security issue or not? On 13/12/12 11:21, Jan Lieskovsky wrote: > Is the user prior building expected to investigate file name of > each of them for sanity? This is where trust boundary is crossed - > someone could send you a tarball: "Here is the source you were > searching for." You would go to build it in Geany.. If Geany is willing to run 'make', as it appears to be, then you already have to trust the sender of a source tree - a Makefile can contain arbitrary shell commands, by design. S
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.