Zsh Mailing List Archive
Messages sorted by:
Reverse Date,
Date,
Thread,
Author
Re: BUG: crafting SHELLOPTS and PS4 allows to run arbitrary programs in setuid binaries using system
On Tue, 27 Sep 2016 10:56:47 +0200
Oliver Kiddle <okiddle@xxxxxxxxxxx> wrote:
> Zsh also needs the prompt_subst option to enable command substitution in
> PS4. Perhaps there's an argument for not importing PS4 from the
> environment in certain cases anyway but I can't see any security issue.
PROMPT_SUBST is enabled in any sh-style emulation, so that's an issue.
I can't offhand think of any way of turning on XTRACE from the
environment, though. Note that $_ is already marked PM_DONTIMPORT.
pws
Messages sorted by:
Reverse Date,
Date,
Thread,
Author