|
|
|
|
|
by jacobwcarlson
3374 days ago
|
|
It's weird that over the course of 7 hours no one on a site called Hacker News noticed that send_email.cpp passes unsanitized user-supplied args to system(). I've spent less than 5 minutes looking at this code, so maybe that's the worst of it. But if 5 minutes of investigation found 1980's style bugs I doubt that's the worst of it. |
|
Complaining about bad data in that situation is like complaining that an admin could hit the power switch.
Or maybe I've completely misunderstood the purpose of this software.