AppImage / AppImage/AppImageKit
AppRun.c appends current directories to various environment variables
- Lenguaje dominante
- Sin datos de lenguaje
- Estrellas
- 9.4k
- Forks
- 588
- Métricas de merge de PR
- Métricas de PR pendientes
Descripción
If user does not have $PATH, $LD_LIBRARY_PATH or $PYTHONPATH defined code https://github.com/probonopd/AppImageKit/blob/c4a7e6da41fc86444ba13eb46ce766efc5623c32/AppRun.c#L166-L170 will leave those environment variables with a single colon at the end. This is not correct: in all three cases empty entry is recognized as “current working directory”, yielding a security risk in some cases. This may also apply to $XDG_DATA_DIRS, $PERLLIB, $GSETTINGS_SCHEMA_DIR and $QT_PLUGIN_PATH, but I am not familiar with applications using these (except for XDG_DATA_DIRS, but from my experience this should be treated on per-application basis).
That file must not have trailing colon if `old_env` appeared to be empty.
Additionally I would not say that silently truncating environment variables if they exceed 2047 characters is a correct behaviour, this may as well yield many kinds of unwanted directories appearing in environment variable.
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Evaluación
Este issue todavía no se ha evaluado.