Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I haven't ran nor looked at the code for PeaZip, but the website describes the program as a GUI wrapper around command line utilities. I highly suspect it's the sub-shell thing.


That's concerning. What if your archive password is ;rm -rf --no-preserve-root /? There might be an easy CVE for the taking here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: