Maybe I should ask what else in the same area? I also use 'popen',
NSTask, and quite a few of the OSA technologies -- of this last
which can serve as an (incoming) Mail rule in 5 of the scripting
languages built-in to OS X.
I'm hard pressed to define the line between user convenience (for
scriptors in my case) and security.
In general, anything that spawns a shell to execute the command can
create this kind of vulnerability. You can determine this typically
by looking at the documentation (it will say that it invokes sh(1) or
the shell). I don't believe that NSTask spawns a shell from my
reading of the documentation.
--
David Duncan
Apple DTS Quartz and Printing
email@hidden
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Carbon-dev mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/carbon-dev/email@hidden