You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I do not see any good reason for .pm files having the executable bit set once they are installed on Unix(-like) platforms. Apparently the install tool (EUMM in both examples) just copies this bit from the original file.
I've not yet found if running a .pm could be exploited to bypass some security restrictions, but that does not mean that doesn't exist.
After thinking a bit more about it this is more a SiteKwalitee metric. I have no idea how this issue is spread on the CPAN and a metric would help to discover.
Check the file permissions in the tarball and report if a
.pm
inlib/
or any.pod
has the execution bit set.Examples:
The text was updated successfully, but these errors were encountered: