On Mon, Mar 9, 2015 at 4:13 PM, Paul Pluzhnikov <ppluzhnikov@gmail.com> wrote: > Attached trivial patch stops wordexp from doing that. BTW, I have no idea how to test the original overflow. Should "setenv(..., NULL, 1)" fail when value==NULL just as it does when name==NULL? Thanks, -- Paul Pluzhnikov