# HG changeset patch # User Bram Moolenaar # Date 1291297694 -3600 # Node ID ef3a3ec8940cb0c55d35d2e5fe924a09d6815f2c # Parent b2789846ed3978ec3dd9a91b6e1ef2f4d054431b updated for version 7.3.070 Problem: Can set environment variables in the sandbox, could be abused. Solution: Disallow it. diff --git a/src/eval.c b/src/eval.c --- a/src/eval.c +++ b/src/eval.c @@ -2326,7 +2326,7 @@ ex_let_one(arg, tv, copy, endchars, op) else if (endchars != NULL && vim_strchr(endchars, *skipwhite(arg)) == NULL) EMSG(_(e_letunexp)); - else + else if (!check_secure()) { c1 = name[len]; name[len] = NUL; diff --git a/src/version.c b/src/version.c --- a/src/version.c +++ b/src/version.c @@ -715,6 +715,8 @@ static char *(features[]) = static int included_patches[] = { /* Add new patch number below this line */ /**/ + 70, +/**/ 69, /**/ 68,