BooK has asked for the wisdom of the Perl Monks concerning the following question:
This is maybe not the best place to ask this question... Anyway,
I noticed a big difference between perl 5.005_03 and 5.6.0... glob behaves quite differently under -T
Try this one-liner:
according to perlsec, this is perfectly normal, and I don't complain... After all, in Perl under 5.6 this was done thanks to a subshell.C:\>perl5.exe -Te "print join', ',glob'*.txt'" Insecure dependency in glob while running with -T switch at -e line 1.
But now try this one:
Well, in Perl 5.6, it is done with File::Glob, so why not.C:\>perl56.exe -Te "print join', ',glob'*.txt'" file1.txt, file2.txt, file3.txt
But if you check in Amelia (page 727), you'll see that it's not the way glob should behave. You'll also notice glob is not in the list of taintedness examples page 560...
So, is this a bug in Perl 5.6? In Amelia? I tried this with ActivePerl 522 and 620, and with Perl 5.005_03 under FreeBSD and Perl 5.6.0 under Linux.
|
---|
Replies are listed 'Best First'. | |
---|---|
5.6 untained glob (Re: glob)
by tye (Sage) on Jan 24, 2001 at 18:54 UTC |
Back to
Seekers of Perl Wisdom