use re 'eval' error

Louis-David Mitterrand vindex+lists-markdown-discuss at apartia.org
Thu Oct 23 14:55:35 EDT 2008


On Thu, Oct 23, 2008 at 05:11:27PM +0200, Aristotle Pagaltzis wrote:

> * Louis-David Mitterrand <vindex+lists-markdown-discuss at apartia.org> [2008-10-23 13:55]:

> > What is the fix?

>

> You have to patch Text::Markdown to add that line to the block

> the regex is in. I see you have already filed a bug against

> Text::Markdown, excellent.


Wouldn't a better fix be to remove the vulnerability from the regex?

In other words isn't "use re 'eval';" weakening the module's security?

Thanks,

--
http://www.lesculturelles.net


More information about the Markdown-Discuss mailing list