Actions
Bug #9976
closedENV doesn't raise SecurityError except for aset and delete
Description
ENV#[]=
と ENV#delete
は$SAFE > 0
のときにtaintedな引数をエラーにしますが、他のメソッドでエラーになりません。
Actions
Like0
Like0Like0Like0
Added by nobu (Nobuyoshi Nakada) almost 11 years ago. Updated over 10 years ago.
Description
ENV#[]=
と ENV#delete
は$SAFE > 0
のときにtaintedな引数をエラーにしますが、他のメソッドでエラーになりません。
Applied in changeset r46547.
hash.c: prohibit tainted strings
Backported into ruby_2_1
branch at r47346.
backported into ruby_2_0_0
at r47492.