FYI Lighttpd 1.4.23 /kernel (trailing '/' on regular file symlink) vulnerability

Dag-Erling Smørgrav des at des.no
Wed May 27 16:44:38 UTC 2009


Eygene Ryabinkin <rea-fbsd at codelabs.ru> writes:
> [new three-part patch]

I committed the namei.h cleanup patch and the vfs_lookup.c comment
patch.

I made a number of changes to the trailing-slash patch.  Can you
double-check it before I commit it?

DES
-- 
Dag-Erling Smørgrav - des at des.no

-------------- next part --------------
A non-text attachment was scrubbed...
Name: vfs_lookup-trailing-slash.diff
Type: text/x-patch
Size: 1848 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-hackers/attachments/20090527/f8c4ea82/vfs_lookup-trailing-slash.bin


More information about the freebsd-hackers mailing list