Parent: 1729ca8692d99ab2c1a269aa79566300de78eb1b
Author: Slawomir Bochenski <lkslawek@gmail.com>
Committer: Marcel Holtmann <marcel@holtmann.org>
Date: 2012-12-04 23:48:41
Tree: 1e27461903a3fea32e48913a267ca7e2d28d2e6c
obexd: Fix valid file name checks for FTP & OPP Until now adversary could exploit OBEX Name header and perform any kind of operations (listing, getting, putting) outside of given root by putting path with ".." components inside this header.
Diffstat
| M | obexd/plugins/filesystem.c | | | 13 | +++++++++++++ |
| M | obexd/plugins/filesystem.h | | | 1 | + |
| M | obexd/plugins/ftp.c | | | 9 | ++++++++- |
| M | obexd/plugins/opp.c | | | 6 | ++++++ |
4 files changed, 28 insertions(+), 1 deletions(-)