Re: majordomo local exploit

From: Chip Salzenberg (chipat_private)
Date: Wed Dec 29 1999 - 23:39:14 PST

  • Next message: Ussr Labs: "Local / Remote GET Buffer Overflow Vulnerability in CamShot"

    According to Henrik Edlund:
    > There is no need, I believe, to use the sysopen function as someone
    > else suggested earlier.
    
    But sysopen() is a simpler approach that eliminates all such concerns,
    and adds robustness.  Simply prepending "< " is not enough to work in
    the presence of, say, filenames that begin with whitespace.
    
    PS: I added sysopen() to Perl 5.4.  :-)
    --
    Chip Salzenberg             - a.k.a. -              <chipat_private>
         "Fleagal.  Bingo.  Drooper.  Snork.  They're cops."   //MST3K
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:24:40 PDT