commons-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Kristian Rosenvold (JIRA)" <j...@apache.org>
Subject [jira] [Created] (IO-484) FilenameUtils should handle embedded null bytes
Date Thu, 06 Aug 2015 11:16:04 GMT
Kristian Rosenvold created IO-484:
-------------------------------------

             Summary: FilenameUtils should handle embedded null bytes
                 Key: IO-484
                 URL: https://issues.apache.org/jira/browse/IO-484
             Project: Commons IO
          Issue Type: Bug
          Components: Utilities
    Affects Versions: 2.4
            Reporter: Kristian Rosenvold
            Assignee: Kristian Rosenvold
             Fix For: 2.5


embedding nulls in filenames exposes injection vectors if the application passes unsanitized
data to some functions in FileNameUtils



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Mime
View raw message