Reviewed: https://review.openstack.org/9268 Committed: http://github.com/openstack/nova/commit/1e218105b08b1afdf944fc77af91c2cadf90b6e2 Submitter: Jenkins Branch: stable/diablo
commit 1e218105b08b1afdf944fc77af91c2cadf90b6e2 Author: Thierry Carrez <email address hidden> Date: Tue Jul 3 16:34:58 2012 +0200
Prevent key/net/md injection writing to host fs
Fix bug 1015531, CVE-2012-3361
Checks that the final normalized path that is about to be written to is always within the mounted guest filesystem.
This is a Diablo backport of the part of Russell Bryant, Pádraig Brady and Mark McLoughlin's Folsom patch that applies to stable/diablo.
Change-Id: I134c40258ff2c9c225bd6092decd9c10e4e22273
Reviewed: https:/ /review. openstack. org/9268 github. com/openstack/ nova/commit/ 1e218105b08b1af df944fc77af91c2 cadf90b6e2
Committed: http://
Submitter: Jenkins
Branch: stable/diablo
commit 1e218105b08b1af df944fc77af91c2 cadf90b6e2
Author: Thierry Carrez <email address hidden>
Date: Tue Jul 3 16:34:58 2012 +0200
Prevent key/net/md injection writing to host fs
Fix bug 1015531, CVE-2012-3361
Checks that the final normalized path that is about to be written
to is always within the mounted guest filesystem.
This is a Diablo backport of the part of Russell Bryant, Pádraig Brady
and Mark McLoughlin's Folsom patch that applies to stable/diablo.
Change-Id: I134c40258ff2c9 c225bd6092decd9 c10e4e22273