On Mon, 2014-10-13 at 06:23 +0200, Dominik George wrote:
> foo='x[$(rm -rf /)]'
> echo $(( foo ))
> Guess when the array index is evaluated? Now mind that it could be 
> user-provided.

In dash it isn't executed which means on Debian at least it's most
harmless.  That's another bouquet for dash.  It's almost enough to make
you forgive the reason it doesn't parse: dash's buggy argument parser.

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to