AppImage / AppImage/AppImageKit
AppRun.c appends current directories to various environment variables
- Dominant language
- No language data
- Stars
- 9.4k
- Forks
- 588
- PR merge metrics
- PR metrics pending
Description
If user does not have $PATH, $LD_LIBRARY_PATH or $PYTHONPATH defined code https://github.com/probonopd/AppImageKit/blob/c4a7e6da41fc86444ba13eb46ce766efc5623c32/AppRun.c#L166-L170 will leave those environment variables with a single colon at the end. This is not correct: in all three cases empty entry is recognized as “current working directory”, yielding a security risk in some cases. This may also apply to $XDG_DATA_DIRS, $PERLLIB, $GSETTINGS_SCHEMA_DIR and $QT_PLUGIN_PATH, but I am not familiar with applications using these (except for XDG_DATA_DIRS, but from my experience this should be treated on per-application basis).
That file must not have trailing colon if `old_env` appeared to be empty.
Additionally I would not say that silently truncating environment variables if they exceed 2047 characters is a correct behaviour, this may as well yield many kinds of unwanted directories appearing in environment variable.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.