Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(553)

Issue 6873012: CHROMIUMOS: Escape | and & characters when passing to the shell. (Closed)

Created:
9 years, 8 months ago by Paul Stewart
Modified:
9 years, 7 months ago
Reviewers:
Sam Leffler, Sumit
CC:
chromium-os-reviews_chromium.org
Visibility:
Public.

Description

CHROMIUMOS: Escape | and & characters when passing to the shell. Add functions for hooks to check validity of domain names and paths. Ensure we set a valid hostname, DNS domain and NIS domain. Document the need for input validation in dhcpcd-run-hooks(8). Fixes CVE-2011-996. Based on patches to dhcpcd-3 by Marius Tomaschewski <mt@suse.de>;. BUG=chromium-os:14192 TEST=Compile and run only -- this code path does not fire in ChromeOS. Our version has all hooks removed so only the escape changes above apply. Change-Id: Ia8c7b3e4af6e13b13319ee7f5cc58f3ab8e02b13 R=sleffler@chromium.org,sumit@chromium.org Committed: http://chrome-svn/viewvc/chromeos?view=rev&revision=cd306c5

Patch Set 1 #

Unified diffs Side-by-side diffs Delta from patch set Stats (+3 lines, -1 line) Patch
M dhcp.c View 1 chunk +3 lines, -1 line 0 comments Download

Messages

Total messages: 2 (0 generated)
Paul Stewart
9 years, 8 months ago (2011-04-15 18:48:26 UTC) #1
Sam Leffler
9 years, 8 months ago (2011-04-17 01:24:40 UTC) #2
LGTM

Powered by Google App Engine
This is Rietveld 408576698