[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Qemu-devel] [PATCH for-3.1 2/2] usb-mtp: outlaw slashes in filename
From: |
Michael Hanselmann |
Subject: |
Re: [Qemu-devel] [PATCH for-3.1 2/2] usb-mtp: outlaw slashes in filenames |
Date: |
Sat, 1 Dec 2018 14:49:35 +0100 |
On 01.12.18 12:55, Philippe Mathieu-Daudé wrote:
> On 30/11/18 20:58, Eric Blake wrote:
>> On 11/30/18 1:08 PM, Philippe Mathieu-Daudé wrote:
>>> On 30/11/18 12:12, Gerd Hoffmann wrote:
>>>> Slash is unix directory separator, so they are not allowed in filenames.
>>>> Note this also stops the classic escape via "../".
>>>>
>>>> Fixes: CVE-2018-16867
>>>> Reported-by: Michael Hanselmann (hansmi.ch)
>>>
>>> It's common for scripts to match '<email>', can you write this one as
>>> Michael Hanselmann <hansmi.ch>?
>>
>> That's not an email address, though. Do we have an email for Michael, or
>> just a username?
>>
>
> I did not notice hehe :)
>
> Per the gpg key: Michael Hanselmann <address@hidden>
> Per git commits: Michael Hanselmann <address@hidden>
It'd be <address@hidden> for this one. Thanks for asking!
Best regards,
Michael
--
https://hansmi.ch/
signature.asc
Description: OpenPGP digital signature