Subject: Re: CRITICAL ** Holes in default cron jobs ** CRITICAL
To: Giles Lean <giles@nemeton.com.au>
From: Jason Thorpe <thorpej@nas.nasa.gov>
List: current-users
Date: 01/02/1997 00:48:50
On Mon, 30 Dec 1996 12:23:12 +1100
Giles Lean <giles@nemeton.com.au> wrote:
> 1. shell metacharacter vulerability of 'ls ... | sh' code
>
> This can be fixed by using 'find ... -print0 | xargs -0 ls ...',
> but the current NetBSD find and xargs programs don't support these
> options.
What, precicely, do these new options do? They're only valuable
if they're necessary (i.e. why add a new option if you don't have do? :-)
Jason R. Thorpe thorpej@nas.nasa.gov
NASA Ames Research Center Home: 408.866.1912
NAS: M/S 258-6 Work: 415.604.0935
Moffett Field, CA 94035 Pager: 415.428.6939