in reply to 'Insecure dependency' warning Systemd::Daemon / IPC::Run3
and that "/home/someone/bin/" had global write access. Someone could put an executable file there and call it something like "ls" or "find" or "wc"; if you were to run a script in this environment, and the script issues a system call to run a program in /bin or /usr/bin (update: but you didn't specify an absolute path for the program), you would end up running whatever happens to be in /home/someone/bin/ instead.PATH=/home/someone/bin:/bin:/usr/bin:/usr/local/bin
If your script always uses absolute paths for commands that it tries to execute via system calls, or if it explicitly controls the PATH setting (and if variables you include in the command string have been taint-checked), the warning should go away.
|
---|