From 143ea06851104ffaa9d3fe8de09c721d2364de64 Mon Sep 17 00:00:00 2001 From: Sami Kerola Date: Mon, 29 May 2017 18:52:17 +0100 Subject: [PATCH] lib: remove _RLD_ from forbid environment variable list The RLD environment variables are related to runtime linker vulnerability in TELNET on systems running Silicon Graphics IRIX. It is extremely unlikely current util-linux would be compiled on such system. Reference: http://www.cert.org/historical/advisories/CA-1995-14.cfm Reference: http://signatures.juniper.net/documentation/signatures/TELNET%3AEXPLOIT%3ASGI-RLD.html Refefence: http://www.polarhome.com/service/man/?qf=rld&tf=2&of=IRIX&sf=1 Signed-off-by: Sami Kerola --- lib/env.c | 1 - 1 file changed, 1 deletion(-) diff --git a/lib/env.c b/lib/env.c index c79e0e0de0..b2e3d975a8 100644 --- a/lib/env.c +++ b/lib/env.c @@ -26,7 +26,6 @@ extern char **environ; #endif static char * const forbid[] = { - "_RLD_=", "BASH_ENV=", /* GNU creeping featurism strikes again... */ "ENV=", "HOME=", -- 2.47.2