In ls.c under the list() function you copy *directory to filename without any bounds checking allowing for possible execution of arbitrary code leading to a system compromise. ~harrison
//for more information contact me at nharrison1989@hotmail.com
Logged In: YES user_id=1833792 Originator: NO
I've uploaded a patch to fix this, see patch #1842291
Log in to post a comment.
Logged In: YES
user_id=1833792
Originator: NO
I've uploaded a patch to fix this, see patch #1842291