in reply to Why do poisoned null attacks still work ?
Yes, it would be quite trivial to get Perl's open-like constructs to fail (actually die) when given a filename matching /\0./s, and that would quite simply be a "good thing" despite all of the apologists in this thread and in p5p (notably excepting ikegami -- thanks). This should also apply to the stat-like constructs, of course.
I encourage you to visit corehackers and submit your patches in that much more receptive environment (compared to p5p). This would be a very nice improvement to Perl's security vulnerabilities.
- tye
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Why do poisoned null attacks still work ? (sanity)
by moritz (Cardinal) on Jul 26, 2009 at 19:15 UTC | |
by tye (Sage) on Jul 26, 2009 at 19:33 UTC | |
by ikegami (Patriarch) on Jul 26, 2009 at 19:28 UTC | |
|
Re^2: Why do poisoned null attacks still work ? (sanity)
by Anonymous Monk on Jul 25, 2009 at 16:05 UTC | |
by ikegami (Patriarch) on Jul 25, 2009 at 17:29 UTC | |
by Anonymous Monk on Jul 26, 2009 at 03:49 UTC | |
by ikegami (Patriarch) on Jul 26, 2009 at 18:59 UTC | |
by Anonymous Monk on Jul 26, 2009 at 19:12 UTC |