Package: libnet-ping-external-perl
Version: 0.10-1
Severity: normal

If the system ping program is not in the current path,
Net::Ping::External's ping function should report its inability to locate
the system ping rather than failing silently.  Alternately, it could
test for a null path, then look in OS-dependent 'standard locations'
for ping, then complain if it still can't be found, but the security
implications of this are troubling.

(While it is rare for shells to have pingless paths, it is not that
uncommon for programmers using taint mode to set $ENV{'PATH'} to '',
then enter the full path to any external programs which may be needed.)

-- System Information
Debian Release: 3.0
Kernel Version: Linux kuno 2.4.23-filter #2 Thu Nov 4 13:17:06 CST 2004 i686 
GNU/Linux

Versions of the packages libnet-ping-external-perl depends on:
ii  perl           5.8.4-8        Larry Wall's Practical Extraction and Report


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to