commit | 6b5d954ec76cb3c1c8bf69e8572ad147ca60cb1d | [log] [tgz] |
---|---|---|
author | Slawomir Bochenski <lkslawek@gmail.com> | Mon Aug 01 15:44:57 2011 +0200 |
committer | Marcel Holtmann <marcel@holtmann.org> | Tue Dec 04 22:48:41 2012 +0100 |
tree | 1e27461903a3fea32e48913a267ca7e2d28d2e6c | |
parent | 1729ca8692d99ab2c1a269aa79566300de78eb1b [diff] |
obexd: Fix valid file name checks for FTP & OPP Until now adversary could exploit OBEX Name header and perform any kind of operations (listing, getting, putting) outside of given root by putting path with ".." components inside this header.