Local root vulnerability in snap-confine
Local root vulnerability in snap-confine
Posted Feb 21, 2022 14:15 UTC (Mon) by zdzichu (subscriber, #17118)In reply to: Local root vulnerability in snap-confine by adobriyan
Parent article: Local root vulnerability in snap-confine
Everything except NULL and / is allowed in filenames. But it doesn't mean it's a good idea to use it. Please take time to read the essay, it is eye-opening.
And you do not need a website. Just touch -- --foot-shooter
(or touch -- -rf\ .
if you like).
Posted Feb 21, 2022 17:33 UTC (Mon)
by adobriyan (subscriber, #30858)
[Link] (1 responses)
GNU ls(1) started to quote filenames with spaces at some point, it was huge step in right direction because copy paste suddenly started working "out of the box". More features lke this are necessary.
Posted Feb 21, 2022 18:04 UTC (Mon)
by Cyberax (✭ supporter ✭, #52523)
[Link]
Just add automatic escaping for such names.
Local root vulnerability in snap-confine
Local root vulnerability in snap-confine