Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <394728b8-b300-9b22-4a74-bff02f447ca8@orlitzky.com>
Date: Wed, 11 Nov 2020 20:37:05 -0500
From: Michael Orlitzky <michael@...itzky.com>
To: oss-security@...ts.openwall.com
Subject: Re: Dash executes code when noexec ("-n") is specified

On 11/11/20 9:12 AM, Michael Orlitzky wrote:
> On 11/11/20 4:40 AM, Jakub Wilk wrote:
>> * Eric Pruitt <eric.pruitt@...il.com>, 2020-11-10, 20:48:
>>>      $ dash -n -c 'echo this should not be executed'
>>>      this should not be executed
>>
>> This was reported in 2017:
>> https://bugs.debian.org/858288
>>
> 
> I forwarded this to Herbert, who maintains Dash and supplied the patch
> on the Debian bug.
> 

And if I was literate, I might have seen this the first time around:

https://git.kernel.org/pub/scm/utils/dash/dash.git/commit/?id=29d6f2148f10213de4e904d515e792d2cf8c968e

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.