Note added to docs cvs.  A putenv() is only active for the duration of the request in 
which the env var was set.  At the end of the request the original environment is 

[2001-05-19 11:26:52] [EMAIL PROTECTED]
Visibility scope of the environment variables set by
putenv() is not documented.  It is important to know whether
an environment variable set in one script can be seen from
another script (served by the same Apache child, for example).

I'm writing a secure application that passes user name and
password in environment varialbles to a setuid C program,
which checks the password against the shadow password file
to authenticate users.  It is crucial for me to know whether
such approach has any security implications, derriving fromt
the visibility scope of environment variables set in PHP.

Many thanks,
Arcady Genkin


