3 msg先週話した件です。
1 msgRe: [edgar: server problems- strange portsa nd ...
4 msgClamav CVE-2006-0162
1 msgRe: listen
2 msgserver problems- strange portsa nd processes
6 msgRe: [SECURITY] [DSA 945-1] New antiword package...
1 msg裲褪瑩 Nh
1 msgRe: [SECURITY] [DSA 938-1] New koffice packages...
1 msgkde 3.5
1 msgGoodbye from our Mailinglist
1 msg[notify] Change of List-Membership details
1 msgWelkom bij Acc Overveen BV mailing list
1 msgBevestigings aanvraag Acc Overveen BV mailing list
5 msgRe: [SECURITY] [DSA 930-1] New smstools package...
3 msgpublic key problem with mirrors.kernel.org

question on having . as LOAD_PATH (ruby)
\ Junichi Uekawa (6 Jan 2006)
. \ Stephen Gran (6 Jan 2006)
. . \ Junichi Uekawa (7 Jan 2006)
. . . \ Junichi Uekawa (7 Jan 2006)
. . . . \ Florian Weimer (7 Jan 2006)

1 msgaruba
8 msgSecurity implications of allowing init to re-ex...
1 msgtest - pls ignore it
1 msgSuperior Medical Support xx
Subject:question on having . as LOAD_PATH (ruby)
Group:Debian-security
From:Junichi Uekawa
Date:6 Jan 2006


 

Hi,

I am wondering what the security implications of having a LOAD_PATH
that includes '.' is.

Debian includes software that is written in ruby, and is executed with
root privilege, such as apt-listbugs.

LOAD_PATH is the list of path that ruby library (MODULE.rb, MODULE.so)
is searched against. The load_path will only fallback to '.' when it
cannot find the required module in other paths, which should normally
not be the case, but I'm feeling a bit uneasy about that.

A theoretical attach scenario is putting a module under /tmp, and wait
until a user executes a ruby script that require's that module with
CWD=/tmp, which also happens not to exist in the other directories
listed in LOAD_PATH.


Example of LOAD_PATH (on my amd64 machine)

$ ruby -e '$:.each{|l| print l+"\n"}'
/usr/local/lib/site_ruby/1.8
/usr/local/lib/site_ruby/1.8/x86_64-linux
/usr/local/lib/site_ruby
/usr/lib/ruby/1.8
/usr/lib/ruby/1.8/x86_64-linux
.




regards,
junichi
--
dancer} Debian Project


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com