URGENT: Security: PINE custom print prompt

Date: Wed, 14 Jan 1998 22:38:22 -0800
From: John Nemeth <jnemeth@cue.bc.ca>
To: csuite-dev@chebucto.ns.ca
Return-Path: <csuite-dev-owner@chebucto.ns.ca>

next message in archive
no next message in thread
previous message in archive
Index of Subjects


     One of my users pointed out this hole to me.  PINE has a feature,
called print-offers-custom-cmd-prompt.  When this is enabled, the
'prYnt' menu has an extra item, '[C]ustom-cmd-prompt'.  Selecting
this, the user can execute anything (i.e. cat /etc/passwd), and the
output will be displayed, along with a menu which allows it to be
printed.  $CS_CONF/pine.conf.fixed must have
'no-print-offers-custom-cmd-prompt' added to the 'feature-list'.

next message in archive
no next message in thread
previous message in archive
Index of Subjects