Re: [exim-dev] [Bug 1604] string-expansion method for readin…

Page principale
Supprimer ce message
Répondre à ce message
Auteur: Jasen Betts
Date:  
À: exim-dev
Sujet: Re: [exim-dev] [Bug 1604] string-expansion method for reading environment variable
On 2015-05-17, admin@??? <admin@???> wrote:
> https://bugs.exim.org/show_bug.cgi?id=1604
>
> --- Comment #1 from Jeremy Harris <jgh146exb@???> ---
> Is there a security implication, as a setuid program trusting environment info
> set up by its callers?


No more than trusting command-line arguments, or input (eg email
headers), provided by the callers.

--
umop apisdn