Re: [PATCH] safelocale

2009-03-01 Thread Chet Ramey
Greg Wooledge wrote: > I wrote this after learning of a security hole in $"..." expansion. > (See http://www.gnu.org/software/gettext/manual/html_node/bash.html > for details of that.) It seems to me that the security hole is the possibility of command substitution, rather than arbitary word expan

[PATCH] safelocale

2009-02-28 Thread Greg Wooledge
I wrote this after learning of a security hole in $"..." expansion. (See http://www.gnu.org/software/gettext/manual/html_node/bash.html for details of that.) It seems the maintainer of gettext is trying to push the use of the portable sh syntax, for example cd $var || error "`eval_gettext \"Can