diff options
| author | gotoyuzo <gotoyuzo@b2dd03c8-39d4-4d8f-98ff-823fe69b080e> | 2008-03-03 14:31:30 +0000 |
|---|---|---|
| committer | gotoyuzo <gotoyuzo@b2dd03c8-39d4-4d8f-98ff-823fe69b080e> | 2008-03-03 14:31:30 +0000 |
| commit | d3c28a3b6a597195b05b9375b9110b85a5d0d241 (patch) | |
| tree | d8dc28281572a27e3d7f438cfc9d2e4c1c107bdf /include/ruby/node.h | |
| parent | 313759c988f2502ba55480a49fd44d6248107ccf (diff) | |
| download | ruby-d3c28a3b6a597195b05b9375b9110b85a5d0d241.tar.gz ruby-d3c28a3b6a597195b05b9375b9110b85a5d0d241.tar.xz ruby-d3c28a3b6a597195b05b9375b9110b85a5d0d241.zip | |
* lib/webrick/httpservlet/filehandler.rb: should normalize path
separators in path_info to prevent directory traversal
attacks on DOSISH platforms.
reported by Digital Security Research Group [DSECRG-08-026].
* lib/webrick/httpservlet/filehandler.rb: pathnames which have
not to be published should be checked case-insensitively.
git-svn-id: http://svn.ruby-lang.org/repos/ruby/trunk@15676 b2dd03c8-39d4-4d8f-98ff-823fe69b080e
Diffstat (limited to 'include/ruby/node.h')
0 files changed, 0 insertions, 0 deletions
