Commit c4d11816 authored by IKEDA Soji's avatar IKEDA Soji
Browse files

Remove undocumented backtick syntax in sympa.conf that allows to execute arbitrary code

parent e1555fc1
......@@ -1728,12 +1728,6 @@ sub _load_config_file_to_hash {
my ($keyword, $value) = ($1, $2);
$value =~ s/\s*$//;
# Special case: `command`
if ($value =~ /^\`(.*)\`$/) {
$value = qx/$1/;
chomp($value);
}
$keyword =
$Sympa::Config::Schema::obsolete_robot_params{$keyword}
// $keyword;
......
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment