Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(61)

Issue 12095045: Merge 175642 (also includes 175980) (Closed)

Created:
7 years, 10 months ago by Chris Evans
Modified:
7 years, 10 months ago
Reviewers:
cpu_(ooo_6.6-7.5)
CC:
chromium-reviews, erikwright+watch_chromium.org, sail+watch_chromium.org
Visibility:
Public.

Description

Merge 175642 (also includes 175980) > Don't allow path traversal paths on the base file helpers > > This forces explicit normalization of paths and make path escaping security bugs much harder to exploit. See for example bug 167122 > > BUG=168890 > TEST=included tests > Review URL: https://codereview.chromium.org/11782005 TBR=cpu@chromium.org Committed: https://src.chromium.org/viewvc/chrome?view=rev&revision=179458

Patch Set 1 #

Unified diffs Side-by-side diffs Delta from patch set Stats (+59 lines, -30 lines) Patch
M base/file_util.h View 1 chunk +1 line, -0 lines 0 comments Download
M base/file_util.cc View 1 chunk +2 lines, -0 lines 0 comments Download
M base/platform_file.h View 1 chunk +12 lines, -2 lines 0 comments Download
M base/platform_file.cc View 1 chunk +12 lines, -0 lines 0 comments Download
M base/platform_file_posix.cc View 3 chunks +17 lines, -15 lines 0 comments Download
M base/platform_file_win.cc View 2 chunks +11 lines, -12 lines 0 comments Download
M chrome/test/base/v8_unit_test.cc View 1 chunk +1 line, -0 lines 0 comments Download
M skia/ext/vector_canvas_unittest.cc View 1 chunk +3 lines, -1 line 0 comments Download

Messages

Total messages: 1 (0 generated)
Chris Evans
7 years, 10 months ago (2013-01-29 23:14:48 UTC) #1

          

Powered by Google App Engine
This is Rietveld 408576698