Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 13 Dec 2012 11:27:35 +0000
From: Simon McVittie <smcv@...ian.org>
To: oss-security@...ts.openwall.com
Subject: Re: Geany IDE not escaping filenames during compilation
 / build - a security issue or not?

On 13/12/12 11:21, Jan Lieskovsky wrote:
> Is the user prior building expected to investigate file name of
> each of them for sanity? This is where trust boundary is crossed -
> someone could send you a tarball: "Here is the source you were
> searching for." You would go to build it in Geany..

If Geany is willing to run 'make', as it appears to be, then you already
have to trust the sender of a source tree - a Makefile can contain
arbitrary shell commands, by design.

    S

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.