Retain orig. filename as suffix for tmp. filename
Adam Byrtek / alpha
alpha at student.uci.agh.edu.pl
Tue Mar 11 00:58:18 UTC 2003
On Mon, Mar 10, 2003 at 07:43:02PM -0500, Pavel Roskin wrote:
> Actually, your patch has created a security hole, but not where I
> expected. extfs_cmd() doesn't quote the local filename. It was OK
> before. But since the local name is now based on the entry name, it must
> be quoted.
Please note that is not the case with plain VFS. Unfortunately I've
just tested it with VFSes. A lesson for me I should not make any
assumptions... and that mc design is still a bit mysterious for me.
Regards
Adam
--
_.|._ |_ _. : Adam Byrtek /alpha/
(_|||_)| |(_| : email alpha@(irc.pl|debian.org)
| : jabber alpha.pl(at)jabber.org, pgp 0xB25952C0
More information about the mc-devel
mailing list