[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kde-commits
Subject:    Re: kdelibs/kate/plugins [POSSIBLY UNSAFE]
From:       Ladislav Strojil <Ladislav.Strojil () seznam ! cz>
Date:       2004-03-08 21:10:30
Message-ID: 200403082210.32835.Ladislav.Strojil () seznam ! cz
[Download RAW message or body]


On Monday 08 of March 2004 22:01, Anders Lund wrote:
> On Monday 08 March 2004 21:42, Anders Lund wrote:
> >   A            autobookmarker/autobookmarker.cpp   1.1 [POSSIBLY UNSAFE:
> > KRun::runCommand] [UNKNOWN] A            autobookmarker/autobookmarker.h
> >   1.1 [UNKNOWN]
>
> Could anyone kindly fill me in on what triggers these warnings?
>
> The code using KRun was copied from another file, which iirc did not
> trigger any warning when it was added, a few years back. And what is the
> UNKNOWN about?

AFAIK the script was added not so long ago (it's not few years back) and it 
checks for licence and for occurence of "evil" commands like "printf", 
"exec", "system" or whatsoever might pose a security risc. It does not say 
the code is unsafe, it just points out that it might be worth double-checking 
the arguments to these functions.

HTH,
Láïa

-- 
    ~       Ladislav Strojil, MFF UK
  ' v '               
 //   \\              
/(     )\    Powered by Penguin.
  ^ ' ^

[Attachment #3 (application/pgp-signature)]

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic