AppImage / AppImage/AppImageKit

AppRun.c appends current directories to various environment variables

オープン
#391 コメント 25 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug help-wanted
主要言語
言語のデータがありません
スター
9.4k
フォーク
588
PR マージ指標
PR 指標を取得中

説明

If user does not have $PATH, $LD_LIBRARY_PATH or $PYTHONPATH defined code https://github.com/probonopd/AppImageKit/blob/c4a7e6da41fc86444ba13eb46ce766efc5623c32/AppRun.c#L166-L170 will leave those environment variables with a single colon at the end. This is not correct: in all three cases empty entry is recognized as “current working directory”, yielding a security risk in some cases. This may also apply to $XDG_DATA_DIRS, $PERLLIB, $GSETTINGS_SCHEMA_DIR and $QT_PLUGIN_PATH, but I am not familiar with applications using these (except for XDG_DATA_DIRS, but from my experience this should be treated on per-application basis).

That file must not have trailing colon if `old_env` appeared to be empty.

Additionally I would not say that silently truncating environment variables if they exceed 2047 characters is a correct behaviour, this may as well yield many kinds of unwanted directories appearing in environment variable.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。