bug-coreutils
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: new snapshot available: coreutils-8.0.108-3aff3


From: Jim Meyering
Subject: Re: new snapshot available: coreutils-8.0.108-3aff3
Date: Sun, 15 Nov 2009 09:37:36 +0100

Gilles Espinasse wrote:
...
>> > Insecure directory in $ENV{PATH} while running with -T switch at - line
> 73.
>>
>> Is some directory in your $PATH group- or world-writable?
>
> should not
> find `echo "$PATH" | sed 's/:/ /g'` -maxdepth 0 -ls
> 1331275    4 drwxr-xr-x   2 root     root         4096 Oct 21 23:07
> /tools_i486/usr/bin
> 1672609    4 drwxr-xr-x   2 root     root         4096 Nov 14 17:56 /bin
> 1672645    4 drwxr-xr-x   2 root     root         4096 Nov 14 17:57 /usr/bin
> 1672640    4 drwxr-xr-x   2 root     root         4096 Nov 14 17:57 /sbin
> 1672648    4 drwxr-xr-x   2 root     root         4096 Nov 14 17:57
> /usr/sbin
> 1672299   12 drwxr-xr-x   2 root     root        12288 Nov 14 17:42
> /tools_i486/bin

That doesn't show the actual value of your $PATH envvar.
I'll bet it starts with ":".  *THAT* is definitely insecure.




reply via email to

[Prev in Thread] Current Thread [Next in Thread]