What makes you believe the script is setuid? The umask is not affecting that at all. Your script is running in taint mode and your command and environment have not been properly de-tainted. Check out perlsec for details.
In reply to Re: setuid - insecure dependancy with backticked cmd?
by derby
in thread setuid - insecure dependancy with backticked cmd?
by EvanK
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |