Hacker News new | past | comments | ask | show | jobs | submit login

> git clone" followed by "./configure" or "make."

Actually, you don't even need to follow it with ./configure or make.. An ext:// git url to clone from will execute arbitrary code:

http://www.vuxml.org/freebsd/7f645ee5-7681-11e5-8519-005056a...




This is a recurring theme within the Unix world — amongst others, vulnerable programs have included tar(1), xterm(1), and vim(1), and they always stem from the eagerness of the authors to provide both the ability to run shell commands, and the ability to run commands from untrusted sources; the fix is to limit the extended ability to trusted sources. But when reported, it (1) gets fixed quickly, and (2) leads to an uproar within the community. Here it has been a wontfix: works as expected, and will likely stay that way.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: