[Pythonmac-SIG] Round 2 with Leopard+Python

Boyd Waters bwaters at nrao.edu
Fri Nov 2 21:49:38 CET 2007


On Nov 2, 2007, at 10:16 AM, Brian Granger wrote:

>  First, if you have set PYTHONPATH to point
> sys.path at the site-packages in /Library, this setting will be lost
> when you do:
>
> sudo python setup.py install


Ouch, another good one...

This is almost certainly not a bug, but rather a security feature.

> The administrator can add a line to the sudoers file:
>
> Defaults  env_reset
>
> that will reset the environment to only contain the variables HOME,  
> LOGNAME,
> PATH, SHELL, TERM, and USER, preventing this attack.





More information about the Pythonmac-SIG mailing list