A movable __pycache__ - vulnerability?
A movable __pycache__ - vulnerability?
Posted Jul 18, 2019 6:09 UTC (Thu) by 0x01 (guest, #112039)In reply to: A movable __pycache__ - vulnerability? by amworsley
Parent article: What's coming in Python 3.8
Posted Jul 18, 2019 8:59 UTC (Thu)
by FLHerne (guest, #105373)
[Link] (2 responses)
Posted Jul 18, 2019 13:43 UTC (Thu)
by kiall (guest, #133240)
[Link]
At the same time a naive admin might `chmod -R ugo+w /`. Having the ability to control where that cache lives is IMO a good thing, even if some admins will make mistakes while using it.
Posted Jul 19, 2019 11:11 UTC (Fri)
by gdamjan (subscriber, #33634)
[Link]
Posted Jul 26, 2019 18:26 UTC (Fri)
by k8to (guest, #15413)
[Link]
Whether this specific case represents a new problem over the other types of env vars that could enable code execution, I'm not really expert enough to comment, but there are blacklist env var approaches in the field, so adding a new such power-env-var can breach those types of defenses.
Posted Jul 27, 2019 4:15 UTC (Sat)
by flussence (guest, #85566)
[Link]
A movable __pycache__ - vulnerability?
A movable __pycache__ - vulnerability?
A movable __pycache__ - vulnerability?
A movable __pycache__ - vulnerability?
A movable __pycache__ - vulnerability?