commit | 9bb99a82ab6939ddeacc27f48018bcd62585ef1b | [log] [tgz] |
---|---|---|
author | G. Campana <gcampana+kvm@quarkslab.com> | Thu Nov 10 16:21:07 2016 +0100 |
committer | Will Deacon <will.deacon@arm.com> | Fri Nov 18 17:43:48 2016 +0000 |
tree | 0156c727ca42b5b666ffc7c6af06ac69204c2719 | |
parent | 1cd6f516264ad2ad83fad3dc1264d6ff4bcd17b2 [diff] |
kvmtool: 9p: fix path traversal vulnerabilities A path traversal exists because the guest can send "../" sequences to the host 9p handlers. To fix this vulnerability, we ensure that path components sent by the guest don't contain "../" sequences. Signed-off-by: G. Campana <gcampana+kvm@quarkslab.com> Signed-off-by: Will Deacon <will.deacon@arm.com>