Bug in busybox base applet?

Denis Vlasenko vda at ilport.com.ua
Thu Sep 1 10:02:46 UTC 2005


On Thursday 01 September 2005 12:52, Vladimir N. Oleynik wrote:
> Denis,
> 
> > ?! where did I run a program from current dir? there is "ls", not "./ls".
> > 
> > My example may happen as follows:
> > 
> > /bin/ls -> /bin/busybox
> 
> But only root can make this symlink and must check before.
> Else you can place /bin/ls to "dd if=/dev/zero of=/dev/hda" ;-)

s:/bin:~/bin in the above. Imagine that
PATH=/bin:/usr/bin:/home/vasia_durachok/bin

Users accidentally deleting their files are not as horrible as
"rm -r /" but still is bad.
--
vda



More information about the busybox mailing list