3 ms·
Same thing happens if I have a: 1) PS1 that displays the current git branch 2) Include the current directory in my PATH Should we file a high severity CVE wi
by x3n0ph3n3 3mo ago
Same thing happens if I have a:
1) PS1 that displays the current git branch
2) Include the current directory in my PATH
Should we file a high severity CVE with bash now?
- jwolfe 3mo agoIf bash placed the current directory in your PATH by default, then yes.
- lyu07282 3mo agoCould file a CVE with Microsoft then, cause thats kinda what cmd.exe is doing: > git clone git://evil evil > cd evil\ > git status The last line would execute git.exe from the cloned repo, wouldn't it?
- loumf 3mo agoIt’s been known for decades that you should never put your current directory in your PATH. There are endless opportunities for vulnerabilities then. I learned this in college in the 80’s (by not following it and getting owned).
- x3n0ph3n3 3mo agoYet PowerShell does it by default.
- julianz 3mo agoI don't think it does? > cd C:\Temp > copy "C:\Program Files\Git\bin\git.exe" .\fred.exe > fred fred: The term 'fred' is not recognized as a name of a cmdlet, function, script file, or executable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try again.
- shitter 3mo agoI would file a CVE for any program that places untrusted content into PATH and invokes non-fully qualified executable names - not for the shell.
- Firehawke 3mo agoNot with bash. If your distro is putting ./ into the path then that's absolutely a high severity CVE with your distro's config.