[issue35755] Remove current directory from posixpath.defpath to enhance security

Christian Heimes report at bugs.python.org
Thu Jan 17 02:41:13 EST 2019


Christian Heimes <lists at cheimes.de> added the comment:

+1, /usr/bin:/bin sounds good to me.

My /usr/include/paths.h has #define _PATH_DEFPATH "/usr/bin:/bin" and #define _PATH_STDPATH "/usr/bin:/bin:/usr/sbin:/sbin". The file is pretty old and has copyright from 89 and 93, https://code.woboq.org/gcc/include/paths.h.html

----------

_______________________________________
Python tracker <report at bugs.python.org>
<https://bugs.python.org/issue35755>
_______________________________________


More information about the Python-bugs-list mailing list