AppImage / AppImage/AppImageKit
AppRun.c appends current directories to various environment variables
- Langage dominant
- Aucune donnée de langage
- Étoiles
- 9.4k
- Forks
- 588
- Métriques de merge des PR
- Métriques de PR en attente
Description
If user does not have $PATH, $LD_LIBRARY_PATH or $PYTHONPATH defined code https://github.com/probonopd/AppImageKit/blob/c4a7e6da41fc86444ba13eb46ce766efc5623c32/AppRun.c#L166-L170 will leave those environment variables with a single colon at the end. This is not correct: in all three cases empty entry is recognized as “current working directory”, yielding a security risk in some cases. This may also apply to $XDG_DATA_DIRS, $PERLLIB, $GSETTINGS_SCHEMA_DIR and $QT_PLUGIN_PATH, but I am not familiar with applications using these (except for XDG_DATA_DIRS, but from my experience this should be treated on per-application basis).
That file must not have trailing colon if `old_env` appeared to be empty.
Additionally I would not say that silently truncating environment variables if they exceed 2047 characters is a correct behaviour, this may as well yield many kinds of unwanted directories appearing in environment variable.
Guide de contribution
Aucun guide de contribution indexé pour ce dépôt
Évaluation
Cette issue n'a pas encore été évaluée.