oss-sec mailing list archives

Re: Potential symlink attack in python3 __pycache__


From: Georgi Guninski <gguninski () gmail com>
Date: Mon, 26 Jul 2021 18:59:30 +0300

On Sat, Jul 24, 2021 at 7:34 PM Michael Orlitzky <michael () orlitzky com> wrote:

When subdirectories of DIR1 are writable by anyone other than the
person running the script, you have a bunch of problems:

  https://bugs.python.org/issue16202

thanks.
python3 shell is still vulnerable from modules in the current
directory, but some of them like |sys| and |os| can't be spoofed.


Current thread: