Funny that this has not been noticed sooner. Maybe it hasn't hurt too many people, since opening '|-' will be followed by exec as a rule, in which case one does have to untaint %ENV{PATH} at some point.
This is one more occasion I really appreciate Perl being Open Source.
In reply to Re: Pipe open triggering environment taint check
by martin
in thread Pipe open triggering environment taint check
by martin
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |