deb vfs security issue (CAN-2004-0494)

Leonard den Ottolander leonard at den.ottolander.nl
Thu Aug 19 01:56:06 UTC 2004


Hi,

On Wed, 2004-08-18 at 19:28, Leonard den Ottolander wrote:
> > http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127973 .
> 
> Attached is a patch that escapes all dangerous characters for function
> arguments. More specifically, everything not in A-Z, a-z, 0-9, _, /, .,
> - and +.

The attached file is a much nicer solution. I believe the original
escaping in mcdebfs_run is redundant as the involved parameters are
passed to mcdebfs_copyout where they will be escaped. Is my use of map
correct?

Leonard.

-- 
mount -t life -o ro /dev/dna /genetic/research

-------------- next part --------------
A non-text attachment was scrubbed...
Name: deb.in.diff
Type: text/x-patch
Size: 864 bytes
Desc: not available
URL: <http://lists.midnight-commander.org/pipermail/mc-devel/attachments/20040819/df3d5072/attachment.bin>


More information about the mc-devel mailing list