Larry Hastings <la...@hastings.org> added the comment:

I still don't understand why this is considered a Python security problem.  If 
the user can put a malicious "python3.dll" at some arbitrary spot in the 
filesystem (e.g. a USB flash drive), and fool Python.exe into loading it, then 
surely they could put an arbitrary executable at that same spot and launch it 
directly.  And that seems way more straightforward.  Why would anyone bother 
with this?

----------

_______________________________________
Python tracker <rep...@bugs.python.org>
<https://bugs.python.org/issue29778>
_______________________________________
_______________________________________________
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com

Reply via email to