You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hello. I was wondering if there was any timescale for applying and making a release with the create/remove functionality. I'd love to use patch.py (just testing it out for the first time today), and this is a blocker. Is there anything missing in the last patch attached here which is lacking/missing which you need a hand with?
@rleigh-dundee hi, glad you find it useful. The last patch lacks a proper security research:
that created files do not fall outside of scope of patch local directory
that API still allows to use patches with absolute paths if people really need them
Patching existing files is already a danger, but creating them opens several new attack vectors. I am not getting time for it, because I am actively looking for a solution to refill my living cost funds, and so far no proposal included the work on patch.py
Actionable items include:
review that filename normalization function is secure
Original issue reported on code.google.com by
[email protected]
on 12 Dec 2014 at 4:25Attachments:
The text was updated successfully, but these errors were encountered: