#13579: test_executable security risk
------------------------------------------------+---------------------------
       Reporter:  vbraun                        |         Owner:  mvngu         
              
           Type:  defect                        |        Status:  needs_review  
              
       Priority:  blocker                       |     Milestone:  sage-5.4      
              
      Component:  doctest                       |    Resolution:                
              
       Keywords:                                |   Work issues:                
              
Report Upstream:  N/A                           |     Reviewers:  Volker Braun, 
Jeroen Demeyer
        Authors:  Jeroen Demeyer, Volker Braun  |     Merged in:                
              
   Dependencies:                                |      Stopgaps:                
              
------------------------------------------------+---------------------------

Comment (by jdemeyer):

 Replying to [comment:9 vbraun]:
 > I'm against including a function that is unsafe by default, thats just
 asking for trouble. `test_executable` either has to `chdir` to ensure that
 the user did not forget it, or refuse to run if `cwd` is writeable by
 anybody but the user.
 The insecurity is not because of `test_executable`, but because of Python.
 So such a check should be added in `spkg/bin/sage` before running `sage-
 run`.

-- 
Ticket URL: <http://trac.sagemath.org/sage_trac/ticket/13579#comment:10>
Sage <http://www.sagemath.org>
Sage: Creating a Viable Open Source Alternative to Magma, Maple, Mathematica, 
and MATLAB

-- 
You received this message because you are subscribed to the Google Groups 
"sage-trac" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/sage-trac?hl=en.

Reply via email to