deb vfs security issue (CAN-2004-0494)
Leonard den Ottolander
leonard at den.ottolander.nl
Thu Aug 19 01:56:06 UTC 2004
Hi,
On Wed, 2004-08-18 at 19:28, Leonard den Ottolander wrote:
> > http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127973 .
>
> Attached is a patch that escapes all dangerous characters for function
> arguments. More specifically, everything not in A-Z, a-z, 0-9, _, /, .,
> - and +.
The attached file is a much nicer solution. I believe the original
escaping in mcdebfs_run is redundant as the involved parameters are
passed to mcdebfs_copyout where they will be escaped. Is my use of map
correct?
Leonard.
--
mount -t life -o ro /dev/dna /genetic/research
-------------- next part --------------
A non-text attachment was scrubbed...
Name: deb.in.diff
Type: text/x-patch
Size: 864 bytes
Desc: not available
URL: <http://lists.midnight-commander.org/pipermail/mc-devel/attachments/20040819/df3d5072/attachment.bin>
More information about the mc-devel
mailing list