Hacker News new | past | comments | ask | show | jobs | submit login

The issue is that the environment isn't a bash-specific thing. Anything can and regularly does set environment variables, and there's no space in there to set a flag for "this is executable" - if it's in the value, anything can set that flag, and the problem here is triggered by programs setting environment variables from external data.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: