Hi all,

> Thinking about this more, I think this introduces a massive security
> vulnerability that it starts allowing shell execution for accounts that
> specify a shell of /sbin/nologin or equivalent.

This is a *very important* and scary observation. I think this can be
a blocker for this patch as-is.

Cheers,

Xabier Oneca_,,_
_______________________________________________
busybox mailing list
[email protected]
https://lists.busybox.net/mailman/listinfo/busybox

Reply via email to