Message174460
| Author |
pitrou |
| Recipients |
Arfrever, Ramchandra Apte, asvetlov, gpolo, mark.dickinson, pitrou, terry.reedy, zach.ware |
| Date |
2012年11月01日.19:55:33 |
| SpamBayes Score |
-1.0 |
| Marked as misclassified |
Yes |
| Message-id |
<1351799734.1.0.290662731143.issue16248@psf.upfronthosting.co.za> |
| In-reply-to |
| Content |
As Zachary and Ramchandra explained, the security issue is obvious: a non-sudoer user A can make a sudoer user B execute arbitrary code, simply by placing a file where IDLE will be run from.
This is the same reason Python has -s and -E options. The least we could do would be to disable readprofile() when sys.flags.ignore_environment is true. |
|