Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix bug forgetting quote PACAPT_DEBUG. #39

Merged
merged 1 commit into from
Mar 13, 2015
Merged

Fix bug forgetting quote PACAPT_DEBUG. #39

merged 1 commit into from
Mar 13, 2015

Conversation

cuonglm
Copy link
Collaborator

@cuonglm cuonglm commented Mar 13, 2015

Forgetting quote variables in shell script leading to many security implications. This pull request fix an issue can make DOS/DDOS attack to machine which run pacapt. Example:

PACAPT_DEBUG='/*/*/*/*/../../../../*/*/*/*/../../../../*/*/*/*' ./pacapt --help

@cuonglm cuonglm mentioned this pull request Mar 13, 2015
icy added a commit that referenced this pull request Mar 13, 2015
Fix bug forgetting quote PACAPT_DEBUG.
@icy icy merged commit cf186e8 into icy:ng Mar 13, 2015
@icy
Copy link
Owner

icy commented Mar 13, 2015

Great #bash lession, @Gnouc :) Thank you very much!

@cuonglm
Copy link
Collaborator Author

cuonglm commented Mar 13, 2015

No problem!

Even shell master commonly forget to quote something like that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants