Bug 761873 (GLUSTER-141) - GF_OPTION_TYPE_PATH should check for presence of ".." in path
Summary: GF_OPTION_TYPE_PATH should check for presence of ".." in path
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: GLUSTER-141
Product: GlusterFS
Classification: Community
Component: core
Version: mainline
Hardware: All
OS: All
low
low
Target Milestone: ---
Assignee: Amar Tumballi
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-07-15 06:53 UTC by Amar Tumballi
Modified: 2013-12-19 00:03 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed:
Regression: RTA
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:


Attachments (Terms of Use)

Description Amar Tumballi 2009-07-15 06:53:08 UTC
and return EINVAL if ".." is found. We should not be permitting a path with entry ".." anywhere in volume file, which can be considered as a security breach.

Comment 1 Anand Avati 2009-07-16 04:37:36 UTC
PATCH: http://patches.gluster.com/patch/757 in master (add strict validatation of GF_OPTION_TYPE_PATH option type.)


Note You need to log in before you can comment on or make changes to this bug.