Re: deb vfs security issue (CAN-2004-0494)



On Wed, 2004-08-18 at 18:40, Jakub Jelinek wrote:
> Also, isn't mcdebfs_copyout's destfile not used just in system ()
> (where it should be escaped), but also in
> if ( open(FILEOUT,">$destfile") )
> (where I'd say it should not be escaped)?

Why not there?

Leonard.

-- 
mount -t life -o ro /dev/dna /genetic/research





[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]