diff options
author | Ingo Schwarze <schwarze@cvs.openbsd.org> | 2014-07-22 18:14:06 +0000 |
---|---|---|
committer | Ingo Schwarze <schwarze@cvs.openbsd.org> | 2014-07-22 18:14:06 +0000 |
commit | db16eddce6318d91b2e043e28bbbecb4a6edef5f (patch) | |
tree | c25308d1058f86d949b38b9a10c12dba1f78f604 /sbin | |
parent | 5c4160212c6bce9b70ebc7410962bfa636d6aac4 (diff) |
Security fix to prevent XSS attacks:
Restrict the character set of strings passed into html_alloc(),
in particular architecture names that come from the QUERY_STRING,
but also SCRIPT_NAME and manpath.conf content for additional safety,
and bail out safely on violations.
Issue reported by Sebastien Marie <semarie-openbsd at latrappe dot fr>.
Diffstat (limited to 'sbin')
0 files changed, 0 insertions, 0 deletions