[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Groff] Re: Bug#107459: pic can be forced to run commands in safe mo
From: |
Werner LEMBERG |
Subject: |
Re: [Groff] Re: Bug#107459: pic can be forced to run commands in safe mode |
Date: |
Sat, 04 Aug 2001 09:29:11 +0200 (CEST) |
> > pic can be forced to execute commands (sh X..X) when running in safe
> > mode (-S). It can be exploited trough lpd when groff/pic is run in
> > print filters, and arbitrary commands with id of lpd can be run.
>
> Are you aware of this problem?
Yes. The very reason that it hasn't been fixed yet is that I need a
free implementation of snprintf() -- additionally I was on vacation.
Should be fixed in the next few weeks.
Werner