GNU bug report logs - #70511
Option to grep into compressed files

Previous Next

Package: grep;

Reported by: Mary <marycada <at> proton.me>

Date: Mon, 22 Apr 2024 06:52:04 UTC

Severity: normal

Full log


View this message in rfc822 format

From: jackson <at> fastmail.com
To: "Paul Eggert" <eggert <at> cs.ucla.edu>, Mary <marycada <at> proton.me>
Cc: 70511 <at> debbugs.gnu.org
Subject: bug#70511: Option to grep into compressed files
Date: Tue, 23 Apr 2024 15:46:01 -0500
Paul Eggert wrote:
> I have some qualms though, as the new option would increase the attack 
> surface for 'grep',

Agreed.

Given the recent uproar involving liblzma being linked into ssh in systemd
builds, resulting in a potentially very dangerous ssh compromise ...

... I would think that minimizing the attack surface on common commands
by not linking in non-essential compression libraries would be a no brainer.

-- 
Paul Jackson
  jackson <at> fastmail.fm




This bug report was last modified 1 year and 40 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.