summaryrefslogtreecommitdiff
path: root/po/ast.po
diff options
context:
space:
mode:
authorGuillem Jover <guillem@debian.org>2014-04-15 08:15:44 +0200
committerGuillem Jover <guillem@debian.org>2014-04-28 15:19:40 +0200
commita82651188476841d190c58693f95827d61959b51 (patch)
tree1ed9d63297e5ef8cfa587cf633a21546612930d3 /po/ast.po
parentd4dfad8cff69c245516abc570d0bba1f614c1443 (diff)
downloaddpkg-a82651188476841d190c58693f95827d61959b51.tar.gz
Dpkg::Source::Patch: Correctly parse C-style diff filenames
We need to strip the surrounding quotes, and unescape any escape sequence, so that we check the same files that the patch program will be using, otherwise a malicious package could overpass those checks, and perform directory traversal attacks on source package unpacking. Fixes: CVE-2014-0471 Reported-by: Jakub Wilk <jwilk@debian.org>
Diffstat (limited to 'po/ast.po')
0 files changed, 0 insertions, 0 deletions