8f7a505
To: vim_dev@googlegroups.com
8f7a505
Subject: Patch 7.3.070
8f7a505
Fcc: outbox
8f7a505
From: Bram Moolenaar <Bram@moolenaar.net>
8f7a505
Mime-Version: 1.0
8f7a505
Content-Type: text/plain; charset=UTF-8
8f7a505
Content-Transfer-Encoding: 8bit
8f7a505
------------
8f7a505
8f7a505
Patch 7.3.070
8f7a505
Problem:    Can set environment variables in the sandbox, could be abused.
8f7a505
Solution:   Disallow it.
8f7a505
Files:	    src/eval.c
8f7a505
8f7a505
8f7a505
*** ../vim-7.3.069/src/eval.c	2010-11-10 20:31:24.000000000 +0100
8f7a505
--- src/eval.c	2010-12-02 14:42:31.000000000 +0100
8f7a505
***************
8f7a505
*** 2326,2332 ****
8f7a505
  	    else if (endchars != NULL
8f7a505
  			     && vim_strchr(endchars, *skipwhite(arg)) == NULL)
8f7a505
  		EMSG(_(e_letunexp));
8f7a505
! 	    else
8f7a505
  	    {
8f7a505
  		c1 = name[len];
8f7a505
  		name[len] = NUL;
8f7a505
--- 2326,2332 ----
8f7a505
  	    else if (endchars != NULL
8f7a505
  			     && vim_strchr(endchars, *skipwhite(arg)) == NULL)
8f7a505
  		EMSG(_(e_letunexp));
8f7a505
! 	    else if (!check_secure())
8f7a505
  	    {
8f7a505
  		c1 = name[len];
8f7a505
  		name[len] = NUL;
8f7a505
*** ../vim-7.3.069/src/version.c	2010-11-24 18:48:08.000000000 +0100
8f7a505
--- src/version.c	2010-12-02 14:46:44.000000000 +0100
8f7a505
***************
8f7a505
*** 716,717 ****
8f7a505
--- 716,719 ----
8f7a505
  {   /* Add new patch number below this line */
8f7a505
+ /**/
8f7a505
+     70,
8f7a505
  /**/
8f7a505
8f7a505
-- 
8f7a505
The only way the average employee can speak to an executive is by taking a
8f7a505
second job as a golf caddie.
8f7a505
				(Scott Adams - The Dilbert principle)
8f7a505
8f7a505
 /// Bram Moolenaar -- Bram@Moolenaar.net -- http://www.Moolenaar.net   \\\
8f7a505
///        sponsor Vim, vote for features -- http://www.Vim.org/sponsor/ \\\
8f7a505
\\\  an exciting new programming language -- http://www.Zimbu.org        ///
8f7a505
 \\\            help me help AIDS victims -- http://ICCF-Holland.org    ///