Closed gdsotirov closed 1 month ago
The two major security issues are
The security alerts say that the command line parser is too complex to fix. Sad.
FYI: here is a list of the forks as of April 2021 that have commits ahead of this official repo. Maybe one of them can take over this project.
omega8cc/lshell 15 commits ahead! smateusjr/lshell SpamExperts/lshell lberra/lshell fy2462/lshell georgpad-zz/lshell deltablue-cloud/lshell doodlecoge/lshell
And here are the 95 current forks (incase someone else forks it tomorrow and fixes everything!)
0mp / lshell 26618929 / lshell affix / lshell akpotter / lshell amift / lshell AnonymousCoward01 / lshell Autisticguy / lshell axelsimon / lshell bbotte / lshell blocky2019 / lshell bnahin / lshell brigriffin / lshell caiqing0204 / lshell chasemp / lshell chaunceyhan / lshell cristicVictory / lshell debackel / lshell deltablue-cloud / lshell devahil / lshell devlato / lshell djoffrey / lshell doodlecoge / lshell Doomfires / lshell dpalominop / lshell dripfeeder / lshell EdwardBetts / lshell fbarbeira / lshell fredericlepied / lshell fy2462 / lshell georgpad-zz / lshell gilshwartz / lshell h-imaoka / lshell hejin / lshell Hodor228 / lshell HtHuanChen / lshell huaichaow / lshell ii0 / lshell jfucanada / lshell jianyongchen / lshell JohnDup / lshell kamade / lshell kofekyzy / lshell LaiJingli / lshell lberra / lshell lbvffvbl / lshell lichi6174 / lshell lionffen / lshell liujunhub / lshell ljhmily / lshell lotapp / lshell Louiehao / lshell lx6XC / lshell makefu / lshell marciopocebon / lshell maulinglawns / lshell msarun003 / lshell neutronstein / lshell olax / lshell omega8cc / lshell p0rietea / lshell pgeof / lshell qiueer / lshell rahulotwani / lshell rahuls-bidgely / lshell RaminNietzsche / lshell rebellion-mobile / lshell regardfs / lshell sadlar / lshell salamander2 / lshell saulwold / lshell Seraf / lshell shammishailaj / lshell simudream / lshell smateusjr / lshell SpamExperts / lshell Spencerx / lshell sqreb / lshell sunytonyli / lshell szaydel / lshell tazjel / lshell tecoholic / lshell trbs / lshell unb-read / lshell Veon / lshell visokos / lshell wgngoo / lshell wjtxt / lshell xbestwiz / lshell yuanguoping / lshell zaxebo1 / lshell zeus911 / lshell zjarci / lshell zouyapeng / lshell zyp0209 / lshell
@salamander2 I'm not sure how you concluded that the security issues are fixed in Omega8CC's fork. Which commits you are referring to? Yeah, the fork is 16 commits ahead now, but these seem just like syncs with origin.
Also I'm really not interested in reviewing all the forks with or without commits ahead, because this neither proves nor solves anything as people sometimes use "Fork" button as "Bookmark". To me the state of the project remains vague (see the issues I referred in issue's description) and I see nothing official from project's author.
P.S. Somehow I've omitted this replay earlier, so I'm writing just now.
@salamander2 I'm not sure how you concluded that the security issues are fixed in Omega8CC's fork.
That's true, there was no real fix, we have "fixed" this simply by blocking all chained commands in the configuration..
If anyone else has any alternative suggestions I would love to hear them!
Here’s one: GNU Rush
Lshell has been updated to address security issues, and version 0.10 has now been released with these changes. If you notice any problems or areas that need fixing, please let me know.
Thanks again for using Lshell, and I apologize for the maintenance delay over the past few years. Have a wonderful day!
I'm opening this as an issue, because I see no option to start a discussion.
Apparently, the project is not being actively maintained anymore (see #188 and #209). There are two open security issues (see CVE-2016-6902 and CVE-2016-6903). Distributions like Fedora has stopped providing packages for this more than two years ago.
I'd like to ask for update on project's status (considering last commit was almost 2 years ago). And more importantly ask for alternatives. Please, share your thoughts and suggestions.