Zsh Mailing List Archive
Messages sorted by: Reverse Date, Date, Thread, Author

Re: BUG: crafting SHELLOPTS and PS4 allows to run arbitrary programs in setuid binaries using system



On Tue, 27 Sep 2016 10:56:47 +0200
Oliver Kiddle <okiddle@xxxxxxxxxxx> wrote:
> Zsh also needs the prompt_subst option to enable command substitution in
> PS4. Perhaps there's an argument for not importing PS4 from the
> environment in certain cases anyway but I can't see any security issue.

PROMPT_SUBST is enabled in any sh-style emulation, so that's an issue.

I can't offhand think of any way of turning on XTRACE from the
environment, though.  Note that $_ is already marked PM_DONTIMPORT.

pws



Messages sorted by: Reverse Date, Date, Thread, Author