OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Advisory: Unchecked system(blaat $var blaat) call in Bugzilla 2.8
From: Todd C. Miller (Todd.MillerCOURTESAN.COM)
Date: Thu May 11 2000 - 01:40:05 CDT


Would it not be simpler (and safer) to just call system() with
a list instead of a scalar and thus prevent perl from ever invoking
a shell?

Ie, instead of:
    system("./processmail $id $::FORM{'who'}");
Use:
    system("./processmail", $id, $::FORM{'who'});

 - todd