#13579: Python sys.path security risk
-------------------------------------------------------+--------------------
       Reporter:  vbraun                               |         Owner:  mvngu  
                                
           Type:  defect                               |        Status:  closed 
                                
       Priority:  blocker                              |     Milestone:  
sage-5.4                               
      Component:  doctest                              |    Resolution:  fixed  
                                
       Keywords:                                       |   Work issues:         
                                
Report Upstream:  Reported upstream. No feedback yet.  |     Reviewers:  Volker 
Braun, Jeroen Demeyer, David Roe
        Authors:  Jeroen Demeyer, Volker Braun         |     Merged in:  
sage-5.4.rc2                           
   Dependencies:                                       |      Stopgaps:         
                                
-------------------------------------------------------+--------------------

Comment (by dimpase):

 Replying to [comment:60 jdemeyer]:

 > I think it's quite unlikely that somebody would doctest the Sage library
 from `/tmp`.

 I did this many times. (But of course I grew up with an idea that the
 worst thing that can happen to your program is that the stack of
 punchcards it is contained in is dropped on the floor and messed up :-))

-- 
Ticket URL: <http://trac.sagemath.org/sage_trac/ticket/13579#comment:75>
Sage <http://www.sagemath.org>
Sage: Creating a Viable Open Source Alternative to Magma, Maple, Mathematica, 
and MATLAB

-- 
You received this message because you are subscribed to the Google Groups 
"sage-trac" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/sage-trac?hl=en.

Reply via email to