deb vfs security issue (CAN-2004-0494)

Andrew V. Samoilov andrew at email.zp.ua
Thu Aug 19 07:51:48 UTC 2004


Hi Leonard,

> On Wed, 2004-08-18 at 21:35, Andrew V. Samoilov wrote:
> > patchfs and uzip is ok ;-) 
> 
> I see. copyin is passed unchecked parameters, but those are quotemeta'd
> with myin. This seems to be the case in most opens, except one: copyout.
> Are you sure 'open 0, "> $out";' is fine?
 
Well `open O,  '>', $out` is more right and secure here and in apt.in, rpms.in .
Patch attached.  Can you commit this one?

vfs/ChangeLog:

patchfs
-- 
Regards,
Andrew V. Samoilov.
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: patchfs.in.patch
URL: <http://lists.midnight-commander.org/pipermail/mc-devel/attachments/20040819/8141b441/attachment.ksh>


More information about the mc-devel mailing list