diff options
author | gotoyuzo <gotoyuzo@b2dd03c8-39d4-4d8f-98ff-823fe69b080e> | 2008-03-03 14:31:30 +0000 |
---|---|---|
committer | gotoyuzo <gotoyuzo@b2dd03c8-39d4-4d8f-98ff-823fe69b080e> | 2008-03-03 14:31:30 +0000 |
commit | 10a0d4b61dd575be73c2e2b6223f1bf7d34c63ea (patch) | |
tree | d8dc28281572a27e3d7f438cfc9d2e4c1c107bdf /doc | |
parent | 7c9e815d940c0b8de7b4a212301c8b1cef62ae2d (diff) | |
download | ruby-10a0d4b61dd575be73c2e2b6223f1bf7d34c63ea.tar.gz |
* lib/webrick/httpservlet/filehandler.rb: should normalize path
separators in path_info to prevent directory traversal
attacks on DOSISH platforms.
reported by Digital Security Research Group [DSECRG-08-026].
* lib/webrick/httpservlet/filehandler.rb: pathnames which have
not to be published should be checked case-insensitively.
git-svn-id: svn+ssh://ci.ruby-lang.org/ruby/trunk@15676 b2dd03c8-39d4-4d8f-98ff-823fe69b080e
Diffstat (limited to 'doc')
0 files changed, 0 insertions, 0 deletions