Re: LYNX-DEV VU#5135 (Lynx vulnerability?) (fwd)

From: Wayne Buttles
Subject: Re: LYNX-DEV VU#5135 (Lynx vulnerability?) (fwd)
Date: Tue, 24 Jun 1997 22:09:37 -0400 (EDT)

On Wed, 25 Jun 1997, H E Nelson wrote:

> Question I have is why it is necessary for Lynx to call `sh' to do a
> `cp'.  Wayne said something about doing an exec().  Why can't this be
> done, or is it not any "safer"?

I just tried it and as I suspected it makes no difference in this case.  I
just suggested it because it seemed safer to not spawn sh every time we
executed a copy command.


