Obviously, the correct way to deal with Shellshock is update bash. However, given that running under Taint mode already requires you to clean up pathing variables before external calls, would it be reasonable to shift best practice to invoking local %ENV = (PATH => '/usr/local/bin'); rather than piecemeal cleanup? Is there any good reason to not wipe the whole %ENV hash before an external call in web context?
#11929 First ask yourself `How would I do this without a computer?' Then have the computer do it the same way.
In reply to Taint and Shellshock by kennethk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |