Re: any concerns about including TZ in AcceptEnv

[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

 



On Tue, 10 Jun 2014, Daniel Kahn Gillmor wrote:

> Hi OpenSSH folks--
> 
> this is more of a configuration question than a development question, i
> think, but:
> 
> Are there any caveats worth being aware of about including the TZ
> variable in AcceptEnv for sshd_config by default?
> 
> I don't see any particular risk, but if there are gotchas people know
> about, i'd be happy to be made aware of them.

some libc accept full paths to TZ files, so if you have any sort of restricted
environment then you'd be trusting the TZ parser there.
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@xxxxxxxxxxx
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev




[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux