On 6/4/19 7:42 AM, Nils Emmerich wrote:

> Bash Version: 5.0
> Patch Level: 0
> Release Status: release
> 
> Description:
>         It is possible to get code execution via a user supplied variable
> in the mathematical context.
>         I don't know if this is considered a bug or not, but if not, I
> think people should be made aware that the mathematical context is unsafe.

The tokens in a mathematical expression undergo a set of word expansions.
If you could post the example you're using we can analyze its behavior.

-- 
``The lyf so short, the craft so long to lerne.'' - Chaucer
                 ``Ars longa, vita brevis'' - Hippocrates
Chet Ramey, UTech, CWRU    c...@case.edu    http://tiswww.cwru.edu/~chet/

Reply via email to