[issue35755] Remove current directory from posixpath.defpath to enhance security

Alexey Izbyshev report at bugs.python.org
Thu Jan 17 17:38:20 EST 2019


Alexey Izbyshev <izbyshev at ispras.ru> added the comment:

Thanks for the info on CS_PATH, Victor. IMHO it'd make sense to use the libc-provided default PATH at least in shutil.which() since its intent is to emulate "which" from the default shell.

----------

_______________________________________
Python tracker <report at bugs.python.org>
<https://bugs.python.org/issue35755>
_______________________________________


More information about the Python-bugs-list mailing list