summaryrefslogtreecommitdiff
path: root/sbin
diff options
context:
space:
mode:
authorIngo Schwarze <schwarze@cvs.openbsd.org>2014-07-22 18:14:06 +0000
committerIngo Schwarze <schwarze@cvs.openbsd.org>2014-07-22 18:14:06 +0000
commitdb16eddce6318d91b2e043e28bbbecb4a6edef5f (patch)
treec25308d1058f86d949b38b9a10c12dba1f78f604 /sbin
parent5c4160212c6bce9b70ebc7410962bfa636d6aac4 (diff)
Security fix to prevent XSS attacks:
Restrict the character set of strings passed into html_alloc(), in particular architecture names that come from the QUERY_STRING, but also SCRIPT_NAME and manpath.conf content for additional safety, and bail out safely on violations. Issue reported by Sebastien Marie <semarie-openbsd at latrappe dot fr>.
Diffstat (limited to 'sbin')
0 files changed, 0 insertions, 0 deletions