diff options
| author | Guido van Rossum <guido@python.org> | 2002-05-31 21:17:53 (GMT) |
|---|---|---|
| committer | Guido van Rossum <guido@python.org> | 2002-05-31 21:17:53 (GMT) |
| commit | 6ad0a79c0705df9eb2a3ddfce187f293497d2ba0 (patch) | |
| tree | 2f175259612098ed929d56cd9bcf1ef7dce78d8c /Python | |
| parent | fed8cc1d3e6a610e35b3c61b1aa15ef633ddd89f (diff) | |
| download | cpython-6ad0a79c0705df9eb2a3ddfce187f293497d2ba0.zip cpython-6ad0a79c0705df9eb2a3ddfce187f293497d2ba0.tar.gz cpython-6ad0a79c0705df9eb2a3ddfce187f293497d2ba0.tar.bz2 | |
Backport to 2.2.x:
SF bug 533625 (Armin Rigo). rexec: potential security hole
If a rexec instance allows writing in the current directory (a common
thing to do), there's a way to execute bogus bytecode. Fix this by
not allowing imports from .pyc files (in a way that allows a site to
configure things so that .pyc files *are* allowed, if writing is not
allowed).
Diffstat (limited to 'Python')
0 files changed, 0 insertions, 0 deletions
