mirror of
https://git.linuxfromscratch.org/lfs.git
synced 2025-06-29 16:49:21 +01:00
clarified the vulnerability with bzgrep
git-svn-id: http://svn.linuxfromscratch.org/LFS/trunk/BOOK@6705 4aa44e1e-78dd-0310-a6d2-fbcd4c07a689
This commit is contained in:
parent
50125deceb
commit
4c2d97d817
@ -36,8 +36,10 @@ GCC, Glibc, and Make</seg></seglistitem>
|
|||||||
|
|
||||||
<screen><userinput>patch -Np1 -i ../&bzip2-docs-patch;</userinput></screen>
|
<screen><userinput>patch -Np1 -i ../&bzip2-docs-patch;</userinput></screen>
|
||||||
|
|
||||||
<para><command>Bzgrep</command> fails to sufficiently sanitise filenames passed
|
<para><command>Bzgrep</command> does not escape '|' and '&' in filenames passed
|
||||||
to it. Apply the following to address this:</para>
|
to it. This allows arbitrary commands to be executed with the privileges of the
|
||||||
|
user running <command>bzgrep</command>. Apply the following to address this:
|
||||||
|
</para>
|
||||||
|
|
||||||
<screen><userinput>patch -Np1 -i ../&bzip2-bzgrep-patch;</userinput></screen>
|
<screen><userinput>patch -Np1 -i ../&bzip2-bzgrep-patch;</userinput></screen>
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user