Are the stream editing coreutils secure against malicious standard in?
Standard scripting utilities such as sed, tr, grep, cat (etc.) can process a stream via standard in and transform it according to some arguments, outputting to STDOUT. I wonder if there are any attack vectors against these, if the attacker… Continue reading Are the stream editing coreutils secure against malicious standard in?





