Bugzilla – Bug 120612
"su" keeps user bin directory first in $PATH
Last modified: 2005-10-06 13:02:38 UTC
Of couse you can never use plain "su" out of the box on someone else's login safely and you never could. The solution is "su -".
*** Bug 120609 has been marked as a duplicate of this bug. ***
That is not true. Up until 9.3 "su" reset $PATH to a secure value
Having a $PATH which looks clean does not mean the environment is "clean". The difference between "su" and "su -" was/is not only overwriting the $PATH variable.